mcp-cli
Warn
Audited by Socket on Jul 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent, but the trust model is weak. The skill installs a core CLI from an unverified GitHub build path, then routes credentials and data through arbitrary npm, Docker, and remote MCP servers, creating disproportionate supply-chain and credential-forwarding risk.
Confidence: 84%Severity: 88%
Audit Metadata