local-mcp-file-editing
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely coherent with its stated purpose as a local filesystem/command MCP server, but it intentionally grants high-impact local execution and can bypass per-command approval via YOLO mode. The install source is publicly verifiable and open-source, which lowers malware concern, yet the publisher/software mismatch and unsandboxed remote-transfer capability make it higher-risk than a normal documentation skill.
Confidence: 86%Severity: 61%
Audit Metadata