moai-library-mermaid

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent, but its execution path is not fully consistent with official Playwright MCP provenance: it runs an unpinned npm package name that I could not verify as the official documented package. No credential harvesting or exfiltration is shown, so this is better classified as a high supply-chain risk than confirmed malware.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Sep 4, 2026, 12:35 PM
Package URL
pkg:socket/skills-sh/rdmptv%2Fadbautoplayer%2Fmoai-library-mermaid%2F@cf63ba7704eae65e5100422034e1cc057bfb3485a2aec6d96d8f31254f09a823
Security Audit — socket — moai-library-mermaid