note-article

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its stated purpose and its publish guardrails are strong, but it relies on a third-party GitHub-hosted MCP server using unofficial note.com APIs and authenticated browser sessions. That supply-chain trust issue is the main concern; the rest of the data flows are broadly proportionate to article drafting and posting.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 26, 2026, 01:30 PM
Package URL
pkg:socket/skills-sh/nanameru%2Fnote-article-skill%2Fnote-article%2F@0f586e4a95f8eb63a28106a1c23072585fc094a7
Security Audit — socket — note-article