pencil-mcp-get-screenshot

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in purpose and data flow, but elevated trust risk remains because the skill depends on a private/unpublished Pencil MCP executable that cannot be independently verified from the cited evidence. No strong signs of credential theft, exfiltration, or scope abuse were found.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 21, 2026, 05:22 PM
Package URL
pkg:socket/skills-sh/partme-ai%2Fpencil-skills%2Fpencil-mcp-get-screenshot%2F@1deb88b95f116eafcadd68b9bf790eaf33bf3430