mcp-management
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core behavior matches MCP management, but the Gemini CLI install instruction is inconsistent with the official package name, creating a meaningful supply-chain risk. Aside from that, config access, tool discovery, and MCP execution are proportionate to purpose, though trust is transitive to configured MCP servers and the Gemini CLI.
Confidence: 89%Severity: 61%
Audit Metadata