auditing-mcp-servers-for-tool-poisoning
Warn
Audited by Socket on Aug 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS/medium risk by design rather than clearly malicious: the skill is coherent with its stated MCP security-audit purpose, but it installs and runs external tooling via official yet weakly pinned paths, may route scanned tool metadata to invariantlabs.ai by default, and includes active SSRF/network probing capabilities. No clear credential theft or deceptive exfiltration is present, but the combination of live probing plus third-party scanner data flow makes it riskier than a passive documentation skill.
Confidence: 87%Severity: 56%
Audit Metadata