touchdesigner-mcp

Warn

Audited by Socket on Aug 28, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

Purpose and capabilities are largely coherent for a TouchDesigner control skill, and the documented MCP traffic stays on localhost. The main risk is supply-chain/install trust: the skill requires a vendor-hosted .tox component with same-org legitimacy but without strong public integrity verification, plus it exposes powerful local code-execution and input-automation features. Overall this is better classified as vulnerable/high-risk rather than malicious.

Confidence: 86%Severity: 78%
AnomalyLOW
scripts/setup.sh

No direct malicious logic (exfiltration, backdoor, reverse shell, or credential theft) is evident in this script. The primary risk is supply-chain trust: it downloads a twozero.tox artifact from a fixed external URL without checksum/signature verification, meaning a compromised or substituted artifact could introduce malicious behavior when later used by TouchDesigner/Hermes. Strengthen by pinning the expected hash/signature and validating after download before writing/using the artifact.

Confidence: 72%Severity: 56%
Audit Metadata
Analyzed At
Aug 28, 2026, 12:49 PM
Package URL
pkg:socket/skills-sh/tt-a1i%2Fhermes-agent%2Ftouchdesigner-mcp%2F@fe23f41ae2bfe41a4e39b9b35a3b5ec9c790504af9ee624fd1e9d2ed66cfacea
Security Audit — socket — touchdesigner-mcp