mo-note

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior is mostly aligned with a Mowen note-listing tool and its apparent data flow matches official Mowen endpoints, but it depends on a local `mocli` binary whose public provenance/install source could not be verified from official documentation. That unverifiable binary requirement drives the main risk; absent stronger proof of `mocli` ownership and release integrity, this should be treated as high supply-chain risk rather than confirmed malware.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
May 8, 2026, 12:47 PM
Package URL
pkg:socket/skills-sh/mowenxd%2Fcli%2Fmo-note%2F@14a84b0158b424a948410e730d7477bcac9c21e2