gate-mcp-claude-installer

Warn

Audited by Socket on Apr 2, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/mcp-fragments/claude/gate-main-npx.json

The fragment itself contains no overt malicious logic, but it creates a high-impact risk path: it executes an externally resolved CLI via npx and passes API credentials into that process environment. The fragment should be reviewed for (a) strict dependency/version pinning and integrity verification for "gate-mcp", and (b) secure secret handling to avoid credential leakage through logs/source control or the executed tool’s behavior.

Confidence: 60%Severity: 62%
AnomalyLOW
SKILL.md

Overall this skill appears coherent with its stated installer purpose and not overtly malicious. The main risks are broad default scope, transitive installation of all Gate skills, and trust in same-org GitHub/script distribution plus remote gatemcp.ai service endpoints; this is better classified as suspicious-to-medium-risk installer behavior than malware.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 2, 2026, 12:24 AM
Package URL
pkg:socket/skills-sh/gate%2Fgate-skills%2Fgate-mcp-claude-installer%2F@754a405035ca80c4995a5064a1f4aeefeb93e6bd
Security Audit — socket — gate-mcp-claude-installer