stale-detector

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities are mostly proportional to a Yuque stale-document audit, and it does not contain deceptive actions, exploit logic, or obvious exfiltration behavior. The main concern is trust: it relies on a third-party yuque-mcp server that receives the user's Yuque token, while the available package provenance is weak and not verifiably tied to Yuque or a clearly established publisher. This is better classified as a supply-chain and credential-forwarding risk than confirmed malware.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Mar 26, 2026, 12:34 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-ecosystem%2Fstale-detector%2F@f724a2f811f39b6582441d4617ba277dd073cd60