NYC

mcp-builder

Pass

Audited by Socket on Feb 16, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Feb 16, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/smithery%2Fai%2Fcomposiohq-mcp-builder%2F@811d85f9b769e2e1cf31c02c2774f7d398f5370a49821f70d46b1bb460a3fc6b