touchdesigner-mcp

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/setup.sh

No direct malicious logic (exfiltration, backdoor, reverse shell, or credential theft) is evident in this script. The primary risk is supply-chain trust: it downloads a twozero.tox artifact from a fixed external URL without checksum/signature verification, meaning a compromised or substituted artifact could introduce malicious behavior when later used by TouchDesigner/Hermes. Strengthen by pinning the expected hash/signature and validating after download before writing/using the artifact.

Confidence: 72%Severity: 56%
Audit Metadata
Analyzed At
Sep 8, 2026, 07:02 PM
Package URL
pkg:socket/skills-sh/hurtzdonut559%2Fhermes-agent%2Ftouchdesigner-mcp%2F@62eb4a349da3d3b6505bcde9cad643530f184e4b85d0d75ce0682db7d852d02a
Security Audit — socket — touchdesigner-mcp