group-tech-design

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s behavior is broadly aligned with its purpose and uses seemingly direct Yuque-style operations, but it requires a group token and routes actions through an external yuque-mcp server with only partially verifiable provenance. This is not confirmed malicious, yet the credential-forwarding and third-party MCP trust make it a medium-risk skill.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 09:12 AM
Package URL
pkg:socket/skills-sh/yuque%2Fyuque-skills%2Fgroup-tech-design%2F@b86456942c3896431b1eb0c22f5805d88fea5b67
Security Audit — socket — group-tech-design