yuque-group-smart-search

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose and workflow are coherent: it performs legitimate group knowledge-base queries using official Yuque MCP tools and synthesizes user-oriented outputs. The credential requirement (group token) is appropriate for group-restricted access. No evidence of malicious behavior (data exfiltration, credential harvesting, or autonomous external actions) is present in the fragments. Primary security considerations are safeguarding the group token, ensuring proper access controls, and validating that document content rendering does not inadvertently leak sensitive material. Overall, the approach appears sound with standard security safeguards recommended for credential handling and content gating.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 07:23 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-plugin%2Fyuque-group-smart-search%2F@f65c9d161481dd7094c490f81f847ad7a6326dfb