mcporter

Warn

Audited by Socket on Jun 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent with its stated purpose and uses largely verifiable distribution channels, so it is not malicious on its face. However, MCPorter is a high-trust bridge: it can execute local stdio server commands and route data, including env-based credentials, to arbitrary configured or direct MCP servers, so the main risk is downstream server trust and broad remote action potential rather than the skill text itself.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Jun 30, 2026, 12:07 PM
Package URL
pkg:socket/skills-sh/zlliang%2Fskills%2Fmcporter%2F@3c53d90663bb8b1c0ca95dc9673ef90632533f4025882309d0340b016eee0605
Security Audit — socket — mcporter