excalidraw

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior is mostly aligned with diagramming, but it depends on executing an unreviewed third-party MCP server cloned from a personal GitHub repo with npm build scripts and no strong release verification. Data flows are otherwise proportionate and mostly local; the main concern is install and execution trust rather than overt malicious behavior.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 10, 2026, 04:52 PM
Package URL
pkg:socket/skills-sh/robonuggets%2Fexcalidraw-skill%2Fexcalidraw%2F@cbac5dfe80bf9a3547096ae04a778b3b636158af