touchdesigner-mcp

Warn

Audited by Socket on Oct 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core TouchDesigner-control purpose matches the capabilities, and the Hermes plugin install path is same-org and coherent. However, the skill relies on a directly downloaded twozero .tox plugin that is not verifiable via an official registry, exposes an unauthenticated local control surface with arbitrary Python execution, includes desktop automation/screen capture, and contains an external transcript/report export path that contradicts the claim that all data stays on localhost.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Oct 6, 2026, 11:58 AM
Package URL
pkg:socket/skills-sh/nousresearch%2Fhermes-plugin-touchdesigner%2Ftouchdesigner-mcp%2F@f8e405bdfa748924efb50b73bb78a7214a8132227df5eea003db28c2ee46ce69