group-onboarding

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The workflow is coherent for onboarding generation and there is no clear malicious behavior in the skill text, but it depends on a non-clearly-official yuque-mcp intermediary that receives broad group-token-backed access to internal docs and member data. Risk is driven mainly by third-party MCP trust and credential forwarding, not by purpose mismatch.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 09:13 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-skills%2Fgroup-onboarding%2F@f2418a679d09b236dace95aea2dc43f9beb2264f
Security Audit — socket — group-onboarding