Back to skill

Security audit

YNote Clip

Security checks across malware telemetry and agentic risk

Overview

This mostly behaves like a YNote web clipper, but it needs review because it includes broad YNote MCP calling ability, a bundled Apify token for Twitter/X clipping, and extra account/local-state checks after saving.

Before installing, confirm you are comfortable with selected webpage content being sent to YNote, Twitter/X clipping being processed through Apify, and the skill having broad YNote MCP helper capabilities. Prefer using your own declared credentials, avoid sourcing a full shell profile, and clean up the /tmp clipping data file after sensitive saves.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.env_credential_access, suspicious.obfuscated_code

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
clip-note.mjs:59

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
static/inject-sdk.fn.js:1