mcp-code-execution-mode
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core purpose mostly matches the capability, but the trust chain is not clean: ara.so branding does not line up with the referenced repo/image publisher, and the documented pip package name appears inconsistent with upstream metadata. The skill also acts as a transitive access bridge to any configured MCP server, including credentialed services and public-posting tools, which materially broadens scope and prompt-injection exposure. No confirmed malware or explicit exfiltration is shown, but the install provenance mismatch and broad proxying make this higher-risk than a typical documentation skill.
Confidence: 89%Severity: 76%
Audit Metadata