add-mcp-tool

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches code edits for an MCP server, but it normalizes exposing arbitrary CLI execution as a new MCP tool without provenance or safety constraints. No clear malware or credential theft is present, yet the command-execution surface is broader than a narrowly scoped integration helper.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 28, 2026, 10:08 PM
Package URL
pkg:socket/skills-sh/mateonunez%2Fnucleo%2Fadd-mcp-tool%2F@57a752c42a30201155f871f746918f37e11ba808