integrate-mcp

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but its actual footprint is too broad and trust-heavy. It fetches arbitrary external content, guides installation/execution of third-party MCPs via npm/pip/git/npx, and forwards user credentials into those integrations without a meaningful verification step. This looks more like a transitive installer for unreviewed external agents than a simple marketplace helper.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
May 20, 2026, 12:43 AM
Package URL
pkg:socket/skills-sh/davekilleen%2FDex%2Fintegrate-mcp%2F@d6813ae85991bd399e6b3afe9318fdbef7d1aabf
Security Audit — socket — integrate-mcp