yuque-group-smart-search

Pass

Audited by Gen Agent Trust Hub on Feb 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill provides a structured workflow for searching and reading documents via a trusted MCP server (yuque-mcp).- [DATA_EXPOSURE]: The skill handles team-level documentation. It identifies the need for a 'group Token' for access control but does not contain hardcoded credentials or expose data to external, non-whitelisted domains.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from document searches. While this represents a standard RAG attack surface, the risk is minimized by the use of specific tool-based retrieval and a structured synthesis format (## 回答, ## 关键要点).
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 28, 2026, 07:21 AM