setup-mcp-connector

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it expands trust to several third-party CLIs and publisher-hosted proxy MCP endpoints, including one flow where a CLI directly receives a user API key. This is not fundamentally incompatible with a connector-setup skill, but the intermediary data flows and credential-forwarding make the footprint medium/high risk rather than benign.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Aug 19, 2026, 01:43 PM
Package URL
pkg:socket/skills-sh/modu-ai%2Fmoai-cowork%2Fsetup-mcp-connector%2F@e5392c71bfb7ba485d836e7af95f3ce7bffaadc130a26faa8dd46dc6bea8f0f4
Security Audit — socket — setup-mcp-connector