darknet-mcp-server-threat-intelligence

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated threat-intelligence purpose, but its footprint is expansive: many external services, Tor access, stealer-log tooling, malware file submission, exploit lookup, and a transitive npx-installed MCP server. I see no confirmed credential theft, hidden exfiltration endpoint, or malicious pre-execution behavior, so this is not malware; however, the breadth of third-party data flows and runtime install trust make it medium risk.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fdarknet-mcp-server-threat-intelligence%2F@782a6bf7a1d4a43f77c24e7c3b0770fafce92e9f9f8c95b9ec0e6e0cb08a5078
Security Audit — socket — darknet-mcp-server-threat-intelligence