thegraph-mcp-skill
Fail
Audited by Socket on Mar 8, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill's footprint is largely coherent with its stated purpose of operating The Graph MCP via uxc, including authenticated access and a help-first inspection workflow. However, there are notable risk signals: reliance on an unverifiable external CLI/binary flow (transitive installation), API key handling that could leak via logs or outputs, and external dependencies that expand the trust surface. Overall, the skill is BENIGN with notable SUSPICIOUS elements due to potential credential exposure and supply-chain risk; require mitigations such as verified binaries, strict credential handling, and explicit data-minimization in logs.
Confidence: 98%
Audit Metadata