scaffold-mcp-server

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This document is a scaffolding instruction for creating MCP servers and does not itself contain malicious code or explicit credential-exfiltration instructions. The primary risks are standard supply-chain and configuration issues: executing package manager installs (un-pinned), reliance on third-party SDKs, and potential mishandling of authentication credentials or stdout protocol. There are no curl|bash download-execute chains, no references to known exfiltration endpoints, and no obfuscated or dynamic code execution patterns inside the provided text. Recommended mitigations: pin dependency versions, review installed SDK/package reputations, ensure handlers avoid printing to stdout for stdio transport, validate middleware correctly handles and stores API keys, and run generated code in isolated environments before production use.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 10:55 PM
Package URL
pkg:socket/skills-sh/pjt222%2Fdevelopment-guides%2Fscaffold-mcp-server%2F@0d7dee50d52bb7268cc15e3825adf5cc9c9906ac