gate-mcp-cursor-installer

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core purpose is installer automation, but its footprint is broader than necessary: it configures multiple MCP endpoints, executes remote npm code, and transitively installs all skills from another repo by default. The data flows are mostly consistent with a Gate ecosystem installer, so this is not confirmed malware, but the transitive installation and unpinned remote code make it a high security-risk skill.

Confidence: 85%Severity: 81%
Audit Metadata
Analyzed At
Mar 14, 2026, 05:02 AM
Package URL
pkg:socket/skills-sh/gate%2Fgate-skills%2Fgate-mcp-cursor-installer%2F@c0c78b7c08f09c109f560a6825cea541337b7b20