mcp-server-setup
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent, but the skill normalizes storing raw credentials in a shared file and forwarding them to npm-fetched MCP server packages, including at least one ambiguously sourced package name. Official npm tooling lowers concern, yet unpinned runtime installs plus credential forwarding to third-party server code create a meaningful supply-chain and secret-exposure risk.
Confidence: 88%Severity: 74%
Audit Metadata