mcporter

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The provided README/manifest describes a legitimate CLI tool with powerful capabilities (running user-specified local commands as stdio endpoints, calling arbitrary URLs, and storing credentials locally). I find no explicit indicators of embedded malicious code, hard-coded secrets, or obfuscation in the text. However, the combination of arbitrary command execution, network calls to user-controlled endpoints, and local JSON credential storage constitutes a moderate security risk: it enables credential forwarding and data exfiltration if the tool is misused or if the npm package distribution is compromised. Recommended mitigations before trusting or deploying: verify package provenance/signature, prefer secure credential storage (OS credential store or encrypted files), restrict/whitelist target domains where feasible, add explicit confirmation prompts for sending credentials or executing commands provided from untrusted sources, and audit the installed package code and install scripts.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:15 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Fmcporter%2F@5b4c2671a49ee33d8301505798aa8c75acf2dec1