MCP Builder

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The MCP Builder fragment provides a coherent set of MCP server patterns but introduces substantial security concerns due to unbounded filesystem access, lack of access controls, and environment-derived credentials exposure risk. While the examples demonstrate legitimate MCP capabilities (tools, resources, prompts, and external data access), real deployments must implement strict sandboxing of rootPath, input validation, authentication/authorization, least-privilege permissions, and secure handling of secrets. Without these safeguards, data leakage, unauthorized modification, or abuse is possible. The material aligns with its purpose but requires strong hardening before production use.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 12:15 AM
Package URL
pkg:socket/skills-sh/yldgio%2Fvibe-vscode%2Fmcp-builder%2F@78cbcf8030e00c1a07bb1155056b067bc78658ea