mcp-inspector

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose matches MCP investigation, but its footprint lets an agent authenticate to arbitrary external servers, persist OAuth credentials, consume untrusted remote content, and execute remote tools with possible side effects. This is coherent with the stated purpose yet still medium-risk because the workflow combines external content ingestion, credential use, and action-taking without strong built-in approval constraints.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:00 PM
Package URL
pkg:socket/skills-sh/mcpjam%2Finspector%2Fmcp-inspector%2F@8bf0ab8ef505c7b0e2b9a938ecbc736d254d3ed6