mcp-to-skill

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The MCP-to-Skill Converter is conceptually coherent: it aims to reduce token overhead by turning stateless MCP tool definitions into on-demand skills and provides a structured, phased workflow for discovery, classification, generation, and validation. There are no evident insecure data flows, credential handling, or unsigned third-party downloads in the described design. While it references potential use of external registries for research and tool invocation, the described approach emphasizes environment configuration, explicit prerequisites, and user-driven execution, which mitigates autonomous risk. Overall, the footprint appears benign and proportionate to the stated objective, though actual implementation would require careful handling of tool mappings and environment-specific constraints to avoid accidental exposure or broken integrations.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 07:10 PM
Package URL
pkg:socket/skills-sh/mathews-tom%2Fpraxis-skills%2Fmcp-to-skill%2F@ed30f8d9bff1f6206d43e71c9843db3f51590fa6