native-mcp
Warn
Audited by Socket on Sep 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's core purpose is coherent, but its actual footprint is broad: it enables execution of arbitrary MCP servers, forwards selected credentials to them, permits remote HTTP MCP endpoints, and auto-exposes discovered tools across all conversations. Official mcp installation is benign, yet the overall design materially increases supply-chain and autonomy risk, especially with unpinned npx/uvx servers and default-enabled sampling for untrusted servers.
Confidence: 89%Severity: 72%
Audit Metadata