mcp-management
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but its footprint materially expands trust by installing arbitrary third-party MCP servers across many agents, often via unpinned npx commands and user-supplied remote URLs. The static findings are mostly documentation false positives, yet the underlying workflow still creates medium security risk from supply-chain exposure and credential forwarding to whatever MCP server/package the user selects.
Confidence: 91%Severity: 58%
Audit Metadata