security-detections-mcp
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core behavior mostly matches the stated purpose, but the skill has medium risk due to unpinned `npx` execution, third-party hosted MCP token forwarding, and autonomous security-engineering workflows. It does not show clear malware or credential-stealing behavior, but it meaningfully expands agent capability and trust in external services.
Confidence: 81%Severity: 58%
Audit Metadata