Socraticode Mcp
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's requirements and instructions are generally coherent for installing a local SocratiCode MCP + Qdrant setup, with one minor mismatch around optional embedding provider environment variables mentioned only in troubleshooting.
This skill appears to do what it says: set up a local SocratiCode MCP server backed by Qdrant and controlled via mcporter. Before installing, verify the upstream packages (mcporter on npm and the socraticode package run via npx) and the GitHub project to ensure you trust them. Be aware: (1) the troubleshooting section mentions OPENAI_API_KEY/EMBEDDING_PROVIDER and Ollama — if you configure external embeddings (OpenAI), your code or derived embeddings may be sent to a third-party service; this is not declared in the metadata and you should only enable it if you understand the privacy implications, (2) npm -g and docker run modify your system environment — prefer running in a controlled or ephemeral environment if you are cautious, and (3) review the socraticode/mcporter packages' source and permissions if you want to be confident nothing unexpected will run during indexing.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
Risk analysis
No visible risk-analysis findings were reported for this release.
