mcp-management

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core behavior matches MCP management, but the Gemini CLI install instruction is inconsistent with the official package name, creating a meaningful supply-chain risk. Aside from that, config access, tool discovery, and MCP execution are proportionate to purpose, though trust is transitive to configured MCP servers and the Gemini CLI.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
Apr 10, 2026, 07:28 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fmcp-management%2F@bb93177c61444773128634ab2dbb0292de7d5d1c
Security Audit — socket — mcp-management