yuque-group-smart-search

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill makes runtime calls to an external service ("yuque-mcp" via the yuque_get_doc tool) to fetch full document content that is injected into the agent's response context and therefore can directly control prompts — flagged dependency: yuque-mcp / yuque_get_doc (external Yuque document fetch).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 07:21 AM