onboarding-guide

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's behavior is largely consistent with its onboarding-guide purpose, but it depends on a non-official third-party yuque-mcp server that receives a group Token and mediates all API calls. The main risk is credential forwarding and trust in community MCP infrastructure, not overt malicious behavior or mismatched capabilities.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
Mar 26, 2026, 12:34 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-ecosystem%2Fonboarding-guide%2F@8e522e1784e8cb87ecd9902d7a6eb4391d35501f