pencil

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in purpose and data flow, but medium-high security risk from depending on a private, non-publicly auditable local MCP binary bundled in an IDE extension. Capabilities are well aligned with design-file editing, with no clear credential theft or exfiltration behavior, yet the unverifiable executable keeps overall risk elevated.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Mar 21, 2026, 05:23 PM
Package URL
pkg:socket/skills-sh/partme-ai%2Fpencil-skills%2Fpencil%2F@f9b665dda9a3d770113eb9e9534abf1c58c36e08