mcp-server-id-mapping

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose is coherent with Cursor MCP troubleshooting, and the flagged command-injection finding is a false positive from documentation syntax. However, it depends on a LegioX MCP server whose public provenance is not verifiable through official package registries or release artifacts, then expects user LEGIOX_* credentials to be passed into that server. That combination makes the install/data-flow trust materially risky even though there is no confirmed malware or overt exfiltration behavior in the skill text itself.

Confidence: 85%Severity: 80%
Audit Metadata
Analyzed At
Sep 8, 2026, 01:41 PM
Package URL
pkg:socket/skills-sh/sonoratek%2Flegiox%2Fmcp-server-id-mapping%2F@61ef8de594f00041a0ffff2bb7e944041130d3dad56c311b2d7389d9f984e511
Security Audit — socket — mcp-server-id-mapping