ableton-live-mcp-control

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's DAW-control capabilities mostly match its purpose, but it delegates setup to a separately owned GitHub repo, uses a mutable clone+pip install path that differs from the project's documented package flow, and exposes powerful arbitrary Python execution inside Ableton. No credential harvesting or off-platform exfiltration is evident, so this is not malicious, but it carries meaningful supply-chain and execution risk.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:40 AM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fableton-live-mcp-control%2F@2663a0f98f04d051459eb1331705daafc274005ffa198243ed8b7808f6d4c60c
Security Audit — socket — ableton-live-mcp-control