mcp-builder

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill appears to be a high-level architectural and implementation guide for building MCP servers, with no code execution, credential handling, or data exfiltration described. Its footprint is coherent with the stated purpose of guiding MCP server development. There are potential data-flow touchpoints to remote documentation through WebFetch, but these are typical for documentation workflows and do not constitute active data leakage. Overall, the security posture is benign, with no evident credential exposure or harmful supply-chain patterns. Treat as a documentation/guidance artifact rather than a runnable tool.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 12:12 AM
Package URL
pkg:socket/skills-sh/ckorhonen%2Fclaude-skills%2Fmcp-builder%2F@9173e2c2107aac82d4ca6c726d71e89d11760470