native-mcp

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core purpose is coherent, but its actual footprint is broad: it enables execution of arbitrary MCP servers, forwards selected credentials to them, permits remote HTTP MCP endpoints, and auto-exposes discovered tools across all conversations. Official mcp installation is benign, yet the overall design materially increases supply-chain and autonomy risk, especially with unpinned npx/uvx servers and default-enabled sampling for untrusted servers.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Sep 8, 2026, 06:55 AM
Package URL
pkg:socket/skills-sh/seaworld008%2Fcommonly-used-high-value-skills%2Fnative-mcp%2F@d987c67da0f54326c1b37b15031acf33e0e6a014b13fd54bb963edcf6187c95e
Security Audit — socket — native-mcp