mcp-skill-gen

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill has meaningful risk from a raw GitHub pipe-to-shell installer, external CLI execution against arbitrary MCP endpoints, and copying local config files into generated artifacts. No clear credential theft or malicious exfiltration is shown, but install trust and data-handling are broader than ideal for a skill generator.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
May 13, 2026, 04:31 AM
Package URL
pkg:socket/skills-sh/vaayne%2Fmcphub%2Fmcp-skill-gen%2F@9b3b9b1808cc004ed9a049a4ce489817968dc32e
Security Audit — socket — mcp-skill-gen