sap-ai-mcp-servers-registry

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's stated purpose as a SAP MCP registry matches its content, so it is not malicious on its own. However, it meaningfully increases trust and credential-forwarding risk by recommending many third-party MCP servers and showing credential-passing config patterns, including unpinned package execution. The footprint is coherent but broader and riskier than a simple read-only registry.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
May 17, 2026, 08:50 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fsap-ai-mcp-servers-registry%2F@02ab8928f4af1b1917d07d0d89fdc21838039dc5
Security Audit — socket — sap-ai-mcp-servers-registry