mcporter-skill

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill fragment is coherent with its stated purpose: it documents and enables management of MCP servers/tools via the mcporter CLI, including auth, calls, and generation. The installation path (Homebrew) and data flows (config directory, user-provided credentials) are typical for a legitimate CLI-based management tool. No hardcoded secrets, suspicious external communications, or anomalous data exfiltration patterns are evident. Minor risk arises from the explicit mention of an exec tool to run mcporter commands, which could be misused if given untrusted inputs, but within the documented usage it remains a normal capability for CLI orchestration.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 09:22 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fmcporter-skill%2F@1232da726684f5aaad4bccc4dc91b89bdaf765e0