mcporter-mcp-first

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its trust boundary is broad. It delegates sensitive internal access through locally configured MCP servers and optionally a third-party bridge, with open-ended downstream endpoints and content sources. This is not confirmed malicious, but it has medium-high security risk from transitive trust, credential forwarding, and prompt-injection exposure.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 11, 2026, 03:16 PM
Package URL
pkg:socket/skills-sh/zereight%2Fskill%2Fmcporter-mcp-first%2F@88bc50ec396766b93198976c294b5804fffb4b6b