moai-design-system

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s behavior mostly matches its design-system purpose and requests proportionate capabilities, but it relies on Pencil MCP tooling that appears official yet is not publicly source-verifiable. No direct credential theft, remote installer, or obviously malicious data routing is present, but the unverifiable external dependency keeps overall risk high.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:19 AM
Package URL
pkg:socket/skills-sh/modu-ai%2Fmoai-adk%2Fmoai-design-system%2F@d4d27b6c5d11dcc32b6d9ad31dd70c94aaca84a3