svelte-mcp
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent for Svelte development, and the install path appears same-org and official in spirit, but the cited executable package name does not match Svelte’s documented package. That mismatch plus unpinned npx execution creates medium supply-chain risk, though there is no evidence of credential theft, hidden execution, or malicious data routing.
Confidence: 90%Severity: 53%
Audit Metadata