onboarding-guide
Warn
Audited by Socket on Mar 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's behavior is largely consistent with its onboarding-guide purpose, but it depends on a non-official third-party yuque-mcp server that receives a group Token and mediates all API calls. The main risk is credential forwarding and trust in community MCP infrastructure, not overt malicious behavior or mismatched capabilities.
Confidence: 85%Severity: 57%
Audit Metadata