weekly-report

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities are mostly coherent, and the data flow matches Yuque reporting. The main concern is trust in the third-party yuque-mcp dependency: registry-hosted but weakly attributable, with credentials forwarded through MCP server code. This is not confirmed malicious, but it carries medium risk due to external dependency provenance and token handling.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
Mar 26, 2026, 12:34 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-ecosystem%2Fweekly-report%2F@ff8dbf1f3abcd32442b81f71c535b239f44a0a8a