security-detections-mcp

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior mostly matches the stated purpose, but the skill has medium risk due to unpinned `npx` execution, third-party hosted MCP token forwarding, and autonomous security-engineering workflows. It does not show clear malware or credential-stealing behavior, but it meaningfully expands agent capability and trust in external services.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
May 20, 2026, 03:16 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fsecurity-skills%2Fsecurity-detections-mcp%2F@a0e412473656e56f7c95d41d8ed53281f3abfa47
Security Audit — socket — security-detections-mcp