mcp-cli-tool
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core behavior fits its stated purpose, but it carries meaningful risk from a same-repo raw GitHub pipe-to-shell installer and from forwarding user secrets to arbitrary configured MCP servers, including third-party HTTP endpoints and spawned server processes. No confirmed malware, prompt theft, or hidden exfiltration is evident, but install trust and credential-routing scope are broader than ideal.
Confidence: 90%Severity: 58%
Audit Metadata