mcp-server-code-execution-mode

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the actual footprint is broader: it installs an unpinned package, relies on a mutable third-party container image, auto-discovers and proxies arbitrary MCP servers, and forwards credentials into those servers. The local config access is expected for bridge setup, yet the combination of weak provenance, credential forwarding, and autonomous external actions makes this a medium-high risk skill rather than a benign narrowly scoped utility.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:35 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fmcp-server-code-execution-mode%2F@1ce79dcb58dae1fc5a33b027ff89ccdb8f658bb68a5d29a2b83d087f6921b2e1
Security Audit — socket — mcp-server-code-execution-mode