mcporter

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the npm install source is coherent and likely official, but the skill's runtime footprint is broad. It can execute arbitrary stdio commands, connect to arbitrary MCP endpoints, and forward credentials/headers to those targets, creating meaningful command-execution and credential-relay risk that is only partly constrained by the stated purpose.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:40 PM
Package URL
pkg:socket/skills-sh/bjesuiter%2Fskills%2Fmcporter%2F@13bfa1324e2e29af881ed96f66c8fdd406a0d1ff