moai-library-mermaid

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main purpose is coherent and there is no clear credential theft or malicious exfiltration, but its runtime trust model is looser than necessary: broad Bash(npx:*) permissions and a mismatched Playwright MCP package reference create meaningful supply-chain and execution risk. Overall this looks like a legitimate documentation/rendering skill with medium security risk rather than malware.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 24, 2026, 11:41 PM
Package URL
pkg:socket/skills-sh/modu-ai%2Fmoai-adk%2Fmoai-library-mermaid%2F@fe678005445c8963a8b77300e6d6e9815bb2e8f7