SocketDevSocketDevOfficialΒ·78 Agent Skills Included

socket-mcp

Dependency security scores and vulnerability checks inside your editor

Checks the security score of any open-source package across npm, PyPI, cargo, Maven, NuGet, RubyGems, and Go. Audits a full package.json and flags risky or vulnerable dependencies before you install them. Runs as a hosted service with OAuth sign-in or as a self-hosted server for full data isolation. Works directly inside Claude, VS Code Copilot, Cursor, and Windsurf with no extra setup.
npx skills add SocketDev/socket-mcp --all -g -y
Available:

Gives the AI agent strict engineering rules for working in this repository, covering commit format, branch safety, tooling choices, and security constraints.

All Skills in This Repository (78)

Pure Emerald Level Indicators
πŸ“¦ In Repo
SocketDevSocketDev

fleet-triaging-findings

Triage raw security-scanner output into prioritized findings with owners.

Official
Advanced
πŸ“¦ In Repo
SocketDevSocketDev

fleet-updating-hooks-dry

Audit fleet hook trees and oxlint plugin configurations for duplication and bloat.

Official
Advanced
πŸ“¦ In Repo
SocketDevSocketDev

fleet-scanning-quality

Orchestrate parallel code scans and generate an A-F prioritized markdown report.

Official
Advanced
πŸ“¦ In Repo
SocketDevSocketDev

fleet-updating-pricing

Fetch current vendor prices and update model-pricing.json with today's date.

Official
Advanced
πŸ“¦ In Repo
SocketDevSocketDev

fleet-scanning-security

Scan CLAUDE config, GitHub Actions, and dependencies to generate an A-F graded security report.

Official
Advanced
πŸ“¦ In Repo
SocketDevSocketDev

fleet-cascading-fleet

Propagate wheelhouse template SHAs and registry pins across fleet repositories.

Official
Advanced
πŸ“¦ In Repo
SocketDevSocketDev

fleet-guarding-paths

Audit and fix path duplication across Socket repositories to enforce canonical path references.

Official
Advanced
πŸ“¦ In Repo
SocketDevSocketDev

fleet-updating-coverage

Run coverage tooling and update the root README coverage badge.

Official
Advanced
πŸ“¦ In Repo
SocketDevSocketDev

fleet-tidying-files

Sweep fleet repositories for junk files and stray temporary directories.

Official
Intermediate
πŸ“¦ In Repo
SocketDevSocketDev

fleet-reordering-release-bump

Relocate a release bump commit to the default branch tip and retag vX.Y.Z.

Official
Advanced
πŸ“¦ In Repo
SocketDevSocketDev

fleet-optimizing-submodules

Determine and apply minimal sparse-checkout patterns for .gitmodules submodules using Bash and Node.js scripts.

Official
Advanced
πŸ“¦ In Repo
SocketDevSocketDev

fleet-auditing-api-surface

Identifies and classifies unused or dead API export subpaths in libraries via fleet-wide analysis.

Official
Intermediate

Frequently Asked Questions

FAQPage Schema
How to install Socket MCP?β–Ό

Run `npx skills add SocketDev/socket-mcp --all -g -y` in your terminal to install all skills in this suite globally.

How to check if a package is safe to install?β–Ό

Ask your AI assistant for the Socket security score of any package and version, and it returns vulnerability and risk data instantly.

Can Socket MCP audit my whole package.json?β–Ό

Yes. It scans every dependency in your package.json in one batch request and flags risky or vulnerable packages.

Does Socket MCP work with Claude and Cursor?β–Ό

Yes. It follows the Model Context Protocol standard and connects to Claude, VS Code Copilot, Cursor, and Windsurf.

Do I need an API key to use Socket MCP?β–Ό

No. The public hosted server uses OAuth sign-in through your browser, so there is no API key to copy or manage.

Related Repositories in Software Engineering

View All in Software Engineering→