mcp-cli

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the trust model is weak. The skill installs a core CLI from an unverified GitHub build path, then routes credentials and data through arbitrary npm, Docker, and remote MCP servers, creating disproportionate supply-chain and credential-forwarding risk.

Confidence: 84%Severity: 88%
Audit Metadata
Analyzed At
Jul 29, 2026, 06:44 AM
Package URL
pkg:socket/skills-sh/obra%2Fdotfiles%2Fmcp-cli%2F@2550140aeb5bb6c4fee5d1de358fc9452372d4e200f248a88a0dbbb90247b294
Security Audit — socket — mcp-cli