create-mcp-app

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill content is coherently aligned with its stated purpose of guiding MCP App creation (tool+resource pairing, host integration, and lifecycle). It relies on official SDKs and widely-used tooling (npm/tsx) and avoids executable downloads from untrusted sources. The data flows and permissions are proportionate to a developer-focused scaffolding/documentation skill, with no evident credential exposure, data exfiltration, or autonomous actions. Overall risk is low-to-moderate (benign to low risk) given the documented patterns; no supply-chain or credential-forwarding patterns are detected in the provided material.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 03:31 PM
Package URL
pkg:socket/skills-sh/modelcontextprotocol%2Fext-apps%2Fcreate-mcp-app%2F@989d5b5a7f8b30e76f554a799f39e9350944e55b