daily-capture

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Likely benign in purpose and scope: the skill's read/write access to Yuque matches note capture and organization. The main concern is trust in the third-party yuque-mcp dependency, which handles a personal Yuque token but is not verifiably official to Yuque and has weak package provenance. This is better classified as suspicious supply-chain/credential-forwarding risk than malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 26, 2026, 12:34 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-ecosystem%2Fdaily-capture%2F@ce819b8e38a227cd222541e60dd9044bb0526585