mcp-provider

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches MCP integration, but the trust model is weak. The skill expands other skills with third-party MCP tools from a broad catalog without clear provenance controls, version pinning, or signature/checksum verification, and it combines external content processing with write/exec-capable tooling.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 17, 2026, 03:05 PM
Package URL
pkg:socket/skills-sh/bacoco%2FEvolveSkill%2Fmcp-provider%2F@f45980091243d94525c14a5d517cbaaa789abf84