endpoint-probe
Warn
Audited by Socket on Aug 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The HTTP probing behavior is broadly aligned with the stated endpoint-discovery purpose and includes reasonable SSRF safeguards, but the MCP stdio feature materially increases risk by allowing package runners to download and execute third-party server code, then forward credentials into those processes. That combination is proportionally risky for a discovery skill and warrants elevated security concern despite not being confirmed malware.
Confidence: 91%Severity: 82%
Audit Metadata