pencil-mcp-search-all-unique-properties

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in purpose and data flow: the skill is narrowly scoped to Pencil design audits and does not collect credentials or route data to external services. However, it depends on a same-org Pencil MCP binary that is not publicly source-verifiable, so the overall security risk remains HIGH under the required unverifiable-binary rule.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Mar 21, 2026, 05:23 PM
Package URL
pkg:socket/skills-sh/partme-ai%2Fpencil-skills%2Fpencil-mcp-search-all-unique-properties%2F@4fa2442939de3a207221d051a47771298913d906