reading-digest
Warn
Audited by Socket on Mar 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's document-reading and note-saving behavior matches its stated purpose, but it depends on a generically named MCP intermediary that receives a personal Yuque token, and the provided provenance evidence for that server is weak and not clearly same-org official. Risk is driven more by install/trust and token-forwarding concerns than by malicious behavior in the skill itself.
Confidence: 86%Severity: 61%
Audit Metadata