mcp-management
Warn
Audited by Socket on Jul 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose matches its capabilities, but it creates a broad execution surface by delegating actions to configured MCP servers and an external CLI. Install sources appear proportionate for developer tooling, yet cross-tool config sharing, external tool execution, and untrusted MCP content make this a medium-to-high security risk rather than clearly benign.
Confidence: 82%Severity: 67%
Audit Metadata