deepseek-claude-code-worker-mcp
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's core purpose is coherent, but its trust model is weak. The main concern is executing MCP code directly from a personal GitHub repository that does not match the skill publisher, while also providing API credentials and code-execution capability. Data flow to DeepSeek appears purpose-consistent, so this is not confirmed malware, but the install and credential-forwarding footprint is too risky to rate benign.
Confidence: 86%Severity: 78%
Audit Metadata