mcp-management

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its footprint materially expands trust by installing arbitrary third-party MCP servers across many agents, often via unpinned npx commands and user-supplied remote URLs. The static findings are mostly documentation false positives, yet the underlying workflow still creates medium security risk from supply-chain exposure and credential forwarding to whatever MCP server/package the user selects.

Confidence: 91%Severity: 58%
Audit Metadata
Analyzed At
Sep 22, 2026, 02:48 AM
Package URL
pkg:socket/skills-sh/codealive-ai%2Fai-driven-development%2Fmcp-management%2F@71d79481fbf0c3a8d217d224fe34987f2417c0f4735cef34750c06c4e49e998e
Security Audit — socket — mcp-management