smart-search
Warn
Audited by Socket on Mar 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's behavior is mostly aligned with its stated purpose, but installer trust is weak because the required yuque-mcp server is not pinned or publisher-verified and would hold a personal Yuque token. No clear malicious behavior or off-purpose data flow is shown, but the ambiguous third-party MCP dependency raises meaningful security risk.
Confidence: 84%Severity: 58%
Audit Metadata