moai-design-system
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s behavior mostly matches its design-system purpose and requests proportionate capabilities, but it relies on Pencil MCP tooling that appears official yet is not publicly source-verifiable. No direct credential theft, remote installer, or obviously malicious data routing is present, but the unverifiable external dependency keeps overall risk high.
Confidence: 83%Severity: 72%
Audit Metadata