auditing-mcp-servers-for-tool-poisoning

Warn

Audited by Socket on Aug 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS/medium risk by design rather than clearly malicious: the skill is coherent with its stated MCP security-audit purpose, but it installs and runs external tooling via official yet weakly pinned paths, may route scanned tool metadata to invariantlabs.ai by default, and includes active SSRF/network probing capabilities. No clear credential theft or deceptive exfiltration is present, but the combination of live probing plus third-party scanner data flow makes it riskier than a passive documentation skill.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Aug 3, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fauditing-mcp-servers-for-tool-poisoning%2F@fcd119284dc2de9a882969539d56070a9d1e38dfc45ef002fec9328220d35ea5
Security Audit — socket — auditing-mcp-servers-for-tool-poisoning