create-mcp-app
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill content is coherently aligned with its stated purpose of guiding MCP App creation (tool+resource pairing, host integration, and lifecycle). It relies on official SDKs and widely-used tooling (npm/tsx) and avoids executable downloads from untrusted sources. The data flows and permissions are proportionate to a developer-focused scaffolding/documentation skill, with no evident credential exposure, data exfiltration, or autonomous actions. Overall risk is low-to-moderate (benign to low risk) given the documented patterns; no supply-chain or credential-forwarding patterns are detected in the provided material.
Confidence: 98%
Audit Metadata