yuque-group-meeting-notes

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's behavior and described network calls are consistent with a legitimate meeting-notes archiving tool. The main security concern is the intermediary MCP and the requirement to supply a group Token: if the MCP service is untrusted or compromised, it could capture meeting content and credentials. There is no evidence of obfuscated or malicious code within the provided description, no local credential harvesting, and no remote code execution patterns. Recommend validating and controlling the yuque-mcp deployment, enforcing least-privilege tokens, and adding explicit instructions for redacting or handling sensitive information before upload.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 07:23 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-plugin%2Fyuque-group-meeting-notes%2F@886eee6444668c621e64813871f4d614c5167a20