touchdesigner-mcp
Warn
Audited by Socket on Oct 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core TouchDesigner-control purpose matches the capabilities, and the Hermes plugin install path is same-org and coherent. However, the skill relies on a directly downloaded twozero .tox plugin that is not verifiable via an official registry, exposes an unauthenticated local control surface with arbitrary Python execution, includes desktop automation/screen capture, and contains an external transcript/report export path that contradicts the claim that all data stays on localhost.
Confidence: 85%Severity: 78%
Audit Metadata