mcp_server_developer
Warn
Audited by Socket on Feb 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Overall, the skill manifest is coherent with its stated purpose of guiding MCP server development for Claude Desktop integration. It outlines plausible architecture, endpoints, telemetry, and NPX distribution workflows. However, explicit user consent for telemetry, strict dependency pinning/audits, and secure CI/CD practices are critical to prevent supply-chain and privacy risks. Treat as SUSPICIOUS-leaning toward BENIGN pending secure implementation details, with emphasis on ensuring consent flows, verified dependencies, and audited telemetry endpoints.
Confidence: 75%Severity: 75%
Audit Metadata