思源笔记增强版
PassAudited by VirusTotal on May 6, 2026.
Findings (1)
The skill bundle provides integration with SiYuan Note for note management, article clipping, and template rendering. However, several files intended for debugging and testing (debug_createdoc.py, test_create_alt.py, and test_create_real.py) contain hardcoded API tokens ('xz1eblvxst0zqcpm') and internal IP addresses ('192.168.1.6'), which represents a credential leakage vulnerability. While the core functionality in siyuan_note.py and siyuan_note_enhanced.py appears to align with the stated purpose, the inclusion of these hardcoded secrets in the distributed bundle is a significant security oversight.
