moai-library-mermaid
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent, but its execution path is not fully consistent with official Playwright MCP provenance: it runs an unpinned npm package name that I could not verify as the official documented package. No credential harvesting or exfiltration is shown, so this is better classified as a high supply-chain risk than confirmed malware.
Confidence: 88%Severity: 72%
Audit Metadata