mcp-server-code-execution-mode

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated purpose matches its main capability: containerized Python used to discover and call MCP tools. However, its real footprint is broad: it executes arbitrary code, launches third-party MCP servers, forwards credentials into them, and enables autonomous external actions. This looks coherent but high-risk rather than overtly malicious; the main concerns are supply-chain trust, credential forwarding, and broad side-effecting automation.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
May 18, 2026, 09:17 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fmcp-server-code-execution-mode%2F@03ad293ffaa125de433ee98978101a10b9c7350b
Security Audit — socket — mcp-server-code-execution-mode