mcp-spy

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill mostly aligns with MCP debugging and uses local logs/localhost endpoints, but it includes a clear approval-bypass command and an unnecessary external Gemini validation path that can leak log content. No confirmed malware or hostile installer was found, yet the permission bypass makes the skill higher risk than a normal documentation guide.

Confidence: 91%Severity: 68%
Audit Metadata
Analyzed At
Sep 16, 2026, 08:27 PM
Package URL
pkg:socket/skills-sh/johnlindquist%2Fclaude%2Fmcp-spy%2F@2e474430eec64863fcec9aa6f76352d579ff6a173a84e7570eebebc3c1eea50b
Security Audit — socket — mcp-spy