mcp-setup

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main purpose is coherent, and the recommended servers are mostly official or plausibly legitimate, but it introduces medium-to-high risk by installing unpinned MCP servers, forwarding credentials to those servers, and allowing arbitrary custom stdio/HTTP MCP endpoints that gain persistent access in future agent sessions.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Apr 19, 2026, 08:55 AM
Package URL
pkg:socket/skills-sh/yeachan-heo%2Foh-my-claudecode%2Fmcp-setup%2F@61153a9603d273eec82637d8895c89d5a2830e20