pencil-mcp-get-screenshot
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN in purpose and data flow, but elevated trust risk remains because the skill depends on a private/unpublished Pencil MCP executable that cannot be independently verified from the cited evidence. No strong signs of credential theft, exfiltration, or scope abuse were found.
Confidence: 87%Severity: 72%
Audit Metadata