mcporter

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and the referenced MCPorter distribution paths are plausibly official, so this is not confirmed malware. However, it is a broad gateway skill: it can discover local MCP configs, authenticate to arbitrary configured servers, and invoke any exposed MCP tool, while `Bash(npx:*)` and unpinned `npx mcporter` increase supply-chain and scope risk. Main concern is overbroad capability and data flow to third-party MCP endpoints, not deceptive install provenance.

Confidence: 83%Severity: 61%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:28 AM
Package URL
pkg:socket/skills-sh/chandima%2Fopencode-config%2Fmcporter%2F@945f9d5b6929e4ddf415be958909badf9c785b94