mcp-graveyard

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s local file access and optional config pruning fit its stated purpose, but its execution model is weaker than advertised: it relies on running an unpinned npm package via npx @latest, and the package/publisher provenance was not verified. No clear credential harvesting, exfiltration endpoint, or disproportionate permissions are present, so this is not malware-like, but the install/execute trust and mutable supply-chain exposure make it medium risk.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
May 7, 2026, 06:27 AM
Package URL
pkg:socket/skills-sh/sfrangulov%2Fskill-graveyard%2Fmcp-graveyard%2F@023a13d30d66fa78b51c86bf57527d201fee297f