mcp-client

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s purpose and capabilities mostly align: a universal MCP client reasonably needs HTTP/stdin transport, schema discovery, and tool invocation. The main concern is broad trust: it can execute arbitrary stdio commands, connect to arbitrary MCP endpoints, and forward tokens to those endpoints. With only official same-org `npx` examples and no obvious stealth or exfiltration service, this looks suspicious-by-scope rather than malicious.

Confidence: 78%Severity: 56%
Audit Metadata
Analyzed At
Jun 23, 2026, 10:26 PM
Package URL
pkg:socket/skills-sh/mjunaidca%2Fcode-execution-mcp-agent-skills%2Fmcp-client%2F@1c56b3f8a68a000abd5e832c762a4fe096ecffc1b00cfe6832d84764b6b08023
Security Audit — socket — mcp-client