native-mcp

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose matches its capabilities: it is an MCP integration guide/client. It is not overtly malicious, and its official `mcp` install path is legitimate. However, the skill intentionally enables broad third-party extension loading, runtime package execution (`npx`/`uvx`/any command), credential forwarding to external servers, auto-injected tools, and default-enabled server-initiated sampling. Those behaviors are coherent for an MCP client but create substantial security exposure if users connect untrusted servers. Overall: suspicious/high-risk integration surface, not confirmed malware.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Apr 27, 2026, 07:09 AM
Package URL
pkg:socket/skills-sh/nousresearch%2Fhermes-agent%2Fnative-mcp%2F@942a20b8e988ec28bcdffb3a1fe362b21c221b13