mcp-light-generator

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly aligned with its stated purpose, but it introduces medium risk by generating and installing a secondary Skill and by proxying an arbitrary upstream MCP package through unpinned `npx` execution. No clear credential theft or exfiltration is present, so this is better classified as suspicious/vulnerable than malicious.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 19, 2026, 02:28 AM
Package URL
pkg:socket/skills-sh/nyosegawa%2Fskills%2Fmcp-light-generator%2F@2dcd764cb084d47e8253e753debe4ad54ddf1235