mcp-cli

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align: it is a shell-oriented wrapper for MCP tools. The main risk is not overt malware but breadth: it can register arbitrary stdio commands and arbitrary HTTP MCP endpoints, then forward credentials and data to them. Package installation looks conventional, but data-flow trust depends entirely on which MCP servers the user adds.

Confidence: 79%Severity: 61%
Audit Metadata
Analyzed At
May 5, 2026, 05:10 PM
Package URL
pkg:socket/skills-sh/wise-toddler%2Fmcp-cli-skill%2Fmcp-cli%2F@82a1c1e2ad3e4e53518324f0e9f4bd711eb8a953