use-mcp

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but it unnecessarily routes MCP operations through Gemini CLI, forwards local context externally, enables auto-approved tool execution, and expands trust to other skills/subagents. The external CLI appears official rather than malicious, so this is a medium-risk delegation and data-flow concern, not confirmed malware.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:29 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fuse-mcp%2F@3d1fdffe7687693aa1d58c8add4ed24daed8f9f7