knowledge-connect

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's read/search/analyze/update capabilities fit its stated Yuque note-linking purpose, and the optional document edits are gated by user confirmation. The main concern is trust in the external yuque-mcp server: the skill names no official publisher, multiple unrelated implementations exist, and the user's Yuque token must be forwarded to that third-party code. Risk is therefore driven more by ambiguous dependency provenance than by the skill logic itself.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 26, 2026, 12:34 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-ecosystem%2Fknowledge-connect%2F@2af3341b4a37ef9834cefe60edfd8c6511e41bab