multi-llm-mcp-server

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches its high-level capabilities, and the install sources appear to be official ecosystems rather than overtly malicious payloads. However, it requests many provider credentials, can route data to multiple external LLMs, and can trigger Codex with full system access. Because the actual LLM_MIX.py code is not provided, data-flow integrity and credential forwarding cannot be verified, so the risk is medium rather than benign.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:35 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fmulti-llm-mcp-server%2F@5f73388d59c5dc3b6f7e25e7d331f224531bdac5840b560946678668bb359aa2
Security Audit — socket — multi-llm-mcp-server