mcp-server-code-execution-mode
Warn
Audited by Socket on May 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s stated purpose matches its main capability: containerized Python used to discover and call MCP tools. However, its real footprint is broad: it executes arbitrary code, launches third-party MCP servers, forwards credentials into them, and enables autonomous external actions. This looks coherent but high-risk rather than overtly malicious; the main concerns are supply-chain trust, credential forwarding, and broad side-effecting automation.
Confidence: 87%Severity: 78%
Audit Metadata