moai-workflow-design-import

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. Path A is well-scoped and includes sensible archive security checks, but the skill’s footprint extends beyond local import by directing the agent to generate and trust additional project-local skills for Figma and Pencil. That transitive trust chain, plus credential use in a generated extractor and an unspecified Pencil MCP provenance, makes the overall skill risk medium despite no direct evidence of malware or overt exfiltration in the reviewed file.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:20 AM
Package URL
pkg:socket/skills-sh/modu-ai%2Fmoai-adk%2Fmoai-workflow-design-import%2F@a43d82a5575b674c6d7842c5d3cbc9397f920040