note-refine

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's read/write document behavior matches its stated note-polishing purpose, but it depends on a non-official, weakly verified yuque-mcp server that holds a Yuque personal token and mediates all document access. The main risk is supply-chain and credential forwarding to community server code, not overt malicious behavior in the skill instructions.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 26, 2026, 12:34 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-ecosystem%2Fnote-refine%2F@5c2f599ad4584e222944d1e73e93d0c9b63f2d4a
Security Audit — socket — note-refine