note-refine
Warn
Audited by Socket on Mar 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's read/write document behavior matches its stated note-polishing purpose, but it depends on a non-official, weakly verified yuque-mcp server that holds a Yuque personal token and mediates all document access. The main risk is supply-chain and credential forwarding to community server code, not overt malicious behavior in the skill instructions.
Confidence: 86%Severity: 74%
Audit Metadata