darknet-mcp-server-threat-intelligence
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly match its stated threat-intelligence purpose, but its footprint is expansive: many external services, Tor access, stealer-log tooling, malware file submission, exploit lookup, and a transitive npx-installed MCP server. I see no confirmed credential theft, hidden exfiltration endpoint, or malicious pre-execution behavior, so this is not malware; however, the breadth of third-party data flows and runtime install trust make it medium risk.
Confidence: 88%Severity: 58%
Audit Metadata