meeting-notes

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior matches its stated purpose, but it depends on an unofficial third-party yuque-mcp bridge that receives a group Token and mediates document creation. Data flows to the official Yuque API are plausible, yet the unverified bridge provenance and credential-forwarding design make this a medium-high security risk rather than benign.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 26, 2026, 12:34 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-ecosystem%2Fmeeting-notes%2F@6ea9c5f0d10ab0e41802bb1acb8cd0dc187a260c