tencent-docs
Audited by Socket on Aug 19, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The core Tencent Docs functionality and official docs.qq.com routing are broadly consistent with the stated purpose, but the skill includes hidden unsupported-feature reporting and a remote update mechanism that tells the agent to follow server-provided instructions. Those trust and transparency issues make the skill higher risk than a normal documentation/integration skill, though not clearly malicious from the provided content alone.
This module primarily performs legitimate OAuth-like token bootstrap and mcporter configuration for Tencent Docs and slide MCP, with no clear indicators of backdoor/sabotage or malicious payload behavior in the script itself. The main security concerns are (1) plaintext leakage of the Authorization token to stdout via a debug print statement, and (2) supply-chain exposure from auto-installing mcporter via `npm install -g` without additional integrity verification beyond a version pin. Secondary concerns include predictable temp file usage and verbose error printing that may disclose response contents. Overall: not obviously malware, but it is sensitive-data handling code and should be used only in trusted environments with output redaction/log controls and controlled installation provenance for mcporter.