Socraticode Mcp

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's requirements and instructions are generally coherent for installing a local SocratiCode MCP + Qdrant setup, with one minor mismatch around optional embedding provider environment variables mentioned only in troubleshooting.

This skill appears to do what it says: set up a local SocratiCode MCP server backed by Qdrant and controlled via mcporter. Before installing, verify the upstream packages (mcporter on npm and the socraticode package run via npx) and the GitHub project to ensure you trust them. Be aware: (1) the troubleshooting section mentions OPENAI_API_KEY/EMBEDDING_PROVIDER and Ollama — if you configure external embeddings (OpenAI), your code or derived embeddings may be sent to a third-party service; this is not declared in the metadata and you should only enable it if you understand the privacy implications, (2) npm -g and docker run modify your system environment — prefer running in a controlled or ephemeral environment if you are cautious, and (3) review the socraticode/mcporter packages' source and permissions if you want to be confident nothing unexpected will run during indexing.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.