OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Warn3 providerslatest audit Apr 18, 2026
Independent checks from skills.sh's audit partners.
The skill installs and uses the 'mcporter' CLI to interact with Model Context Protocol (MCP) servers. It allows the agent to execute shell commands and make network requests. This functionality, while useful for MCP integration, creates a significant security risk if the agent is manipulated into running malicious commands or exfiltrating data via tool parameters.
Detected behaviors
No alerts
1 issue