yapi

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s YApi query/sync purpose is plausible, but it depends on a third-party personal skill/package chain, installs another skill transitively, and forwards YApi credentials into that external CLI. Data flow mostly matches the stated purpose, yet install trust and credential forwarding are disproportionate enough to warrant medium-high risk.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Apr 13, 2026, 07:38 AM
Package URL
pkg:socket/skills-sh/leeguooooo%2Fcross-request-master%2Fyapi%2F@a3d5626cebee36231e359c9b2605b05c3b89dc57