mcp-security-hub

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is internally consistent with its stated purpose, but that purpose is high risk: it equips an AI agent with offensive security and active testing capabilities, broad network reach, container execution, local file access via mounts, and optional credential forwarding. This looks more like a transparent offensive-security enablement skill than malware, but it is still dangerous and should be classified as high-risk/suspicious rather than benign.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:35 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fmcp-security-hub%2F@4aa96f797023c7198565497d9e9077d64b27ce88665d8466ef0b6541a429731f
Security Audit — socket — mcp-security-hub