smart-summary
Warn
Audited by Socket on Mar 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s read-only summarization behavior is purpose-aligned, but it relies on an externally operated yuque-mcp layer that receives a personal Yuque token and document contents. The main risk is credential and content forwarding to an insufficiently verified intermediary, not overt malicious behavior.
Confidence: 84%Severity: 64%
Audit Metadata