mcp-server-builder

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
references/server-implementation.md

The code is not overtly malicious, but the TypeScript MCP server contains high-impact command-injection risks because untrusted tool arguments are embedded in execSync shell commands. The unrestricted review_code file path also permits arbitrary readable-file disclosure. The Python command execution shown is materially safer due to its fixed allowlist and non-shell subprocess invocation. Inputs should be validated and passed as argument arrays, shell execution should be avoided, and file paths should be restricted to the project root. No evidence of credential theft, persistence, network exfiltration, or other intentional malware is present in the supplied fragment.

Confidence: 98%Severity: 88%
Audit Metadata
Analyzed At
Sep 19, 2026, 02:17 AM
Package URL
pkg:socket/skills-sh/borghei%2Fclaude-skills%2Fmcp-server-builder%2F@aff40d2033f896aa401d10bd95b3815f56736e3e1bf9d14c3e407d9c398ac1a1
Security Audit — socket — mcp-server-builder