cve-mcp-server-security-intelligence

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities and data flows are broadly consistent with a vulnerability-intelligence MCP server, and credentials appear intended for official vendor APIs rather than a proxy. The main concern is install trust: ara.so is presented as the skill publisher, but the actual software is sourced from a separate personal GitHub account and a differently named PyPI maintainer, with unpinned installs. That mismatch makes the footprint not fully trust-coherent, though there is no direct evidence of credential theft, covert exfiltration, or malicious payload behavior in the provided skill text.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:33 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fcve-mcp-server-security-intelligence%2F@498cab3a0ae3c6189060c901722dea099722124f87cd184002bbd4bc11d57278
Security Audit — socket — cve-mcp-server-security-intelligence