Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- clip-note.mjs:59
Security audit
Security checks across malware telemetry and agentic risk
This mostly behaves like a YNote web clipper, but it needs review because it includes broad YNote MCP calling ability, a bundled Apify token for Twitter/X clipping, and extra account/local-state checks after saving.
Before installing, confirm you are comfortable with selected webpage content being sent to YNote, Twitter/X clipping being processed through Apify, and the skill having broad YNote MCP helper capabilities. Prefer using your own declared credentials, avoid sourcing a full shell profile, and clean up the /tmp clipping data file after sensitive saves.
66/66 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access, suspicious.obfuscated_code