affine-mcp-server-integration
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities fit its stated AFFiNE integration purpose, and there is no sign of covert exfiltration, prompt-stealing, or malicious pre-execution behavior. However, it routes sensitive AFFiNE credentials to a community-published MCP server/CLI rather than official AFFiNE software, with unpinned install examples and optional remote deployment, creating a meaningful supply-chain and credential-forwarding risk.
Confidence: 90%Severity: 66%
Audit Metadata