fiddler-mcp-setup

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches most of its behavior and the main API flow is local and officially documented by Telerik. However, the Claude Desktop branch introduces a disproportionate trust boundary by fetching and executing third-party `mcp-remote` code from npm and forwarding the Fiddler API key to it, creating a high supply-chain and credential-forwarding risk. Non-Claude paths look broadly coherent; the Desktop bridge is the main reason this should not be classified benign.

Confidence: 93%Severity: 84%
Audit Metadata
Analyzed At
Apr 20, 2026, 03:00 PM
Package URL
pkg:socket/skills-sh/telerik%2Ffiddler-agent-tools%2Ffiddler-mcp-setup%2F@a288ecbbdec097c4c3765febd947e59b08d74b29