local-mcp-file-editing

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated purpose as a local filesystem/command MCP server, but it intentionally grants high-impact local execution and can bypass per-command approval via YOLO mode. The install source is publicly verifiable and open-source, which lowers malware concern, yet the publisher/software mismatch and unsandboxed remote-transfer capability make it higher-risk than a normal documentation skill.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Flocal-mcp-file-editing%2F@1b152f691b052cf4b840939a4e462cc68d6e093a0257dea1da5b23dd89dc1b95
Security Audit — socket — local-mcp-file-editing