mcp-cli

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the trust story is weak because the skill assumes an unspecified mcp-cli executable whose provenance does not cleanly map to official MCP tooling. Capabilities are broad but generally aligned with MCP; the main risks are unverifiable dependency provenance, downstream data exposure through configured servers, and a shell-executing example that could propagate unsafe input.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 21, 2026, 08:43 PM
Package URL
pkg:socket/skills-sh/involvex%2Fawesome-copilot%2Fmcp-cli%2F@7f4ae3a3cf2b9bd394ac60ab93db4471e6a0b61b