pi-mcp-adapter

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, and the flagged command-injection items are documentation artifacts, not executable payloads. However, the skill materially expands trust by reading secret-bearing MCP configs and forwarding credentials to externally configured MCP servers while encouraging unpinned npx installs of third-party packages; combined with the ara.so vs package-owner mismatch, this is medium-high supply-chain and credential-forwarding risk rather than confirmed malware.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:35 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fpi-mcp-adapter%2F@879c584a784174ac08cf718af99d94c661fa44970023e5f6f377a0ae2372c7e0
Security Audit — socket — pi-mcp-adapter