yuque

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose and capabilities mostly align, and there is no obvious malware pattern or remote installer. The main concern is credential forwarding of Yuque cookies/tokens into an unreviewed local helper, especially the browser-cookie mode using Yuque's internal web API, which leaves endpoint and exfiltration behavior unverifiable from the skill text alone.

Confidence: 77%Severity: 58%
Audit Metadata
Analyzed At
Aug 24, 2026, 05:43 PM
Package URL
pkg:socket/skills-sh/acedatacloud%2Fskills%2Fyuque%2F@d2e8fd0678b55269e7bf830cb6842b85cead7ffbc050f6da23f0f174dd82b857
Security Audit — socket — yuque