mcp-discovery

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent with its stated purpose, but its purpose is to install and activate third-party MCP servers, creating notable transitive supply-chain and tool-surface expansion risk. The official registry and zero-env restriction reduce credential risk, but the mandatory registry-first behavior and lack of visible package verification keep overall risk elevated.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Aug 26, 2026, 04:47 AM
Package URL
pkg:socket/skills-sh/hmbown%2Fcodewhale%2Fmcp-discovery%2F@1707abdba2a16f715d473730723e52d702203a5bb454f9913873958516d0ac8d
Security Audit — socket — mcp-discovery