tech-design

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The capability fits the stated purpose, and the requested Yuque group token is plausible for saving docs to team repos. The main issue is install/execution trust: the skill depends on a not-clearly-official yuque-mcp server from personal publishers, which becomes a high-value credential and data handling intermediary. This is not confirmed malicious, but the third-party MCP trust boundary and credential forwarding make it medium-to-high risk.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 26, 2026, 12:36 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-ecosystem%2Ftech-design%2F@ddef1fcebe8c838a99cf91c28df6896ace5086d7