cve-mcp-server-security-intelligence
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities and data flows are broadly consistent with a vulnerability-intelligence MCP server, and credentials appear intended for official vendor APIs rather than a proxy. The main concern is install trust: ara.so is presented as the skill publisher, but the actual software is sourced from a separate personal GitHub account and a differently named PyPI maintainer, with unpinned installs. That mismatch makes the footprint not fully trust-coherent, though there is no direct evidence of credential theft, covert exfiltration, or malicious payload behavior in the provided skill text.
Confidence: 89%Severity: 58%
Audit Metadata