using-mcp

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core MCP discovery/call workflow matches the stated purpose, but the skill’s trust boundary is broad. Its main risk is that it lets the agent add arbitrary stdio or HTTP MCP servers, forward env vars to them, and execute unpinned third-party server packages; that is proportionate to MCP administration but materially expands supply-chain and credential exposure.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:28 AM
Package URL
pkg:socket/skills-sh/dtyq%2Fmagic%2Fusing-mcp%2F@dcab41f28f0f0f119f83e248ac722509d3ce0548
Security Audit — socket — using-mcp