mcp-cli

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its footprint is too trust-heavy for a simple MCP helper. It requires a third-party CLI from a personal GitHub repo using clone/build instructions, then routes user data and sometimes credentials into external npm packages, Docker images, and remote MCP endpoints. No confirmed malware or hidden exfiltration is shown, but the install provenance and credential-forwarding patterns make this a high-risk skill.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Sep 16, 2026, 12:05 AM
Package URL
pkg:socket/skills-sh/obra%2Fsuperpowers-lab%2Fmcp-cli%2F@2550140aeb5bb6c4fee5d1de358fc9452372d4e200f248a88a0dbbb90247b294
Security Audit — socket — mcp-cli