mcp-grep-code

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated behavior is coherent and its network destination fits the purpose, but it relies on a third-party personal GitHub CLI installed via unpinned `curl|sh`. That installer/binary trust mismatch is disproportionate for a simple code-search skill and creates a high supply-chain risk even without evidence of overt credential theft.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Mar 13, 2026, 02:05 PM
Package URL
pkg:socket/skills-sh/vaayne%2Fcc-plugins%2Fmcp-grep-code%2F@ccd5479d53b498ab3d83921dd788ca30a84c3409