MCP Builder

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The MCP Builder fragment provides a coherent set of MCP server patterns but introduces substantial security concerns due to unbounded filesystem access, lack of access controls, and environment-derived credentials exposure risk. While the examples demonstrate legitimate MCP capabilities (tools, resources, prompts, and external data access), real deployments must implement strict sandboxing of rootPath, input validation, authentication/authorization, least-privilege permissions, and secure handling of secrets. Without these safeguards, data leakage, unauthorized modification, or abuse is possible. The material aligns with its purpose but requires strong hardening before production use.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 12:15 AM
Package URL
pkg:socket/skills-sh/yldgio%2Fvibe-vscode%2Fmcp-builder%2F@78cbcf8030e00c1a07bb1155056b067bc78658ea
Security Audit — socket — MCP Builder