mcp-spy
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill mostly aligns with MCP debugging and uses local logs/localhost endpoints, but it includes a clear approval-bypass command and an unnecessary external Gemini validation path that can leak log content. No confirmed malware or hostile installer was found, yet the permission bypass makes the skill higher risk than a normal documentation guide.
Confidence: 91%Severity: 68%
Audit Metadata