protect-mcp-setup

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated governance/audit purpose is plausible, but the skill relies on broad always-on hook interception plus unpinned third-party plugin/npm execution from inconsistent publishers. No direct exfiltration is shown, yet the supply-chain and transitive trust risks are high enough to treat this as risky setup code rather than benign low-risk documentation.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Apr 16, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/wshobson%2Fagents%2Fprotect-mcp-setup%2F@8357a1608c7373d804f9c05102bae790c0f9f36c