tencent-docs

Warn

Audited by Socket on Aug 19, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Tencent Docs functionality and official docs.qq.com routing are broadly consistent with the stated purpose, but the skill includes hidden unsupported-feature reporting and a remote update mechanism that tells the agent to follow server-provided instructions. Those trust and transparency issues make the skill higher risk than a normal documentation/integration skill, though not clearly malicious from the provided content alone.

Confidence: 81%Severity: 58%
AnomalyLOW
setup.sh

This module primarily performs legitimate OAuth-like token bootstrap and mcporter configuration for Tencent Docs and slide MCP, with no clear indicators of backdoor/sabotage or malicious payload behavior in the script itself. The main security concerns are (1) plaintext leakage of the Authorization token to stdout via a debug print statement, and (2) supply-chain exposure from auto-installing mcporter via `npm install -g` without additional integrity verification beyond a version pin. Secondary concerns include predictable temp file usage and verbose error printing that may disclose response contents. Overall: not obviously malware, but it is sensitive-data handling code and should be used only in trusted environments with output redaction/log controls and controlled installation provenance for mcporter.

Confidence: 68%Severity: 60%
Audit Metadata
Analyzed At
Aug 19, 2026, 05:35 PM
Package URL
pkg:socket/skills-sh/hk-hub%2Fagentskills%2Ftencent-docs%2F@9b596e54b976797139be3190ff22078d26ab2a392b1454d25b4217dda58d6d08
Security Audit — socket — tencent-docs