mcp-cli
Warn
Audited by Socket on May 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and capabilities mostly align: it is a shell-oriented wrapper for MCP tools. The main risk is not overt malware but breadth: it can register arbitrary stdio commands and arbitrary HTTP MCP endpoints, then forward credentials and data to them. Package installation looks conventional, but data-flow trust depends entirely on which MCP servers the user adds.
Confidence: 79%Severity: 61%
Audit Metadata