using-mcp
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core MCP discovery/call workflow matches the stated purpose, but the skill’s trust boundary is broad. Its main risk is that it lets the agent add arbitrary stdio or HTTP MCP servers, forward env vars to them, and execute unpinned third-party server packages; that is proportionate to MCP administration but materially expands supply-chain and credential exposure.
Confidence: 87%Severity: 64%
Audit Metadata