pencil-uiux-design

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's capabilities are coherent for UI/UX design and its data flows appear local and proportionate, but it depends on Pencil MCP tooling that external evidence describes as private-source and not independently verifiable. There is no strong sign of credential theft or exfiltration in this skill itself; the main concern is supply-chain/install trust from the required closed-source MCP dependency.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 2, 2026, 02:59 PM
Package URL
pkg:socket/skills-sh/guercheLE%2Fmy-skills%2Fpencil-uiux-design%2F@39853d4c5d85e87fc943eddd7c182364c01a597f