deepseek-claude-code-worker-mcp

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, but its trust model is weak. The main concern is executing MCP code directly from a personal GitHub repository that does not match the skill publisher, while also providing API credentials and code-execution capability. Data flow to DeepSeek appears purpose-consistent, so this is not confirmed malware, but the install and credential-forwarding footprint is too risky to rate benign.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fdeepseek-claude-code-worker-mcp%2F@23d9fc067399813979394615e138857af94ecd96f15a2833ce5bc40d4295e6c1
Security Audit — socket — deepseek-claude-code-worker-mcp