group-onboarding
Warn
Audited by Socket on May 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The workflow is coherent for onboarding generation and there is no clear malicious behavior in the skill text, but it depends on a non-clearly-official yuque-mcp intermediary that receives broad group-token-backed access to internal docs and member data. Risk is driven mainly by third-party MCP trust and credential forwarding, not by purpose mismatch.
Confidence: 100%Severity: 60%
Audit Metadata