Yuque Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Yuque Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
中文说明: README.zh-CN.md
This folder is prepared for building a custom MCP server for Yuque.
Build a Yuque MCP server so Codex can:
list/add/remove)get_my_repositories, get_repository_overview, search_and_read, create_document_with_toc)docs/00-project-brief.mddocs/01-scope-v1.mddocs/02-architecture.mddocs/03-tool-contract.mddocs/04-api-mapping.mddocs/05-security.mddocs/06-implementation-plan.mddocs/07-test-plan.mddocs/08-codex-integration.mddocs/09-release-notes-zh.mddocs/10-registry-publish.mddocs/11-weekly-maintenance.mddocs/12-complaint-and-takedown.mdCHANGELOG.mdCONTRIBUTING.mdSECURITY.mdDISCLAIMER.mdtasks/TODO.mdIn your new Codex session, start with:
docs/01-scope-v1.md and docs/03-tool-contract.md.npm install
npm run buildRequired env:
YUQUE_TOKENYUQUE_ENDPOINT (optional, default https://www.yuque.com/api/v2/)YUQUE_TIMEOUT_MS (optional, default 10000)YUQUE_MAX_RETRIES (optional, default 2, read-only retries only)YUQUE_ALLOW_WRITE (optional, default false)YUQUE_WRITE_NAMESPACE_ALLOWLIST (optional, comma-separated namespace allowlist for repo/doc/toc writes)YUQUE_WRITE_GROUP_ALLOWLIST (optional, comma-separated group login allowlist for group writes)YUQUE_ALLOW_DELETE (optional, default false)YUQUE_DELETE_NAMESPACE_ALLOWLIST (optional, comma-separated delete allowlist targets; namespace for repo/doc, login for group)YUQUE_FILE_ROOT (optional, default current working directory, used by file-based doc tools)YUQUE_FILE_MAX_BYTES (optional, default 1048576)YUQUE_FILE_ALLOWED_EXTENSIONS (optional, default .md,.markdown,.txt)Write safety:
YUQUE_ALLOW_WRITE=true to enable writes.YUQUE_WRITE_NAMESPACE_ALLOWLIST=team/sandbox,team/testYUQUE_WRITE_GROUP_ALLOWLIST=sandbox-teamDelete safety:
yuque_delete_doc, yuque_delete_repo, and yuque_delete_group are blocked by default.YUQUE_ALLOW_WRITE=trueYUQUE_ALLOW_DELETE=trueYUQUE_DELETE_NAMESPACE_ALLOWLIST=your/test-namespace,your-test-group-loginconfirm: true and exact confirm_text:DELETE DOC <namespace>/<docRef>DELETE REPO <namespace>DELETE GROUP <login>Latest highlights:
yuque_get_doc / yuque_update_doc / yuque_delete_doc support either slug or doc_id.yuque_list_docs supports pagination (offset, limit).yuque_search_docs now scans paginated docs across the full repository.markdown, html, lake; visibility supports 0 | 1 | 2.editNode, url, open_window, visible).yuque_list_group_users, yuque_add_group_user, yuque_remove_group_user.Run in dev:
npm run devRun compiled server:
npm run startRun local MCP smoke test (test namespace only):
YUQUE_SMOKE_NAMESPACE=your/test-namespace npm run smokeRun write smoke suite with cleanup (create/update/toc/delete on test namespace):
YUQUE_SMOKE_NAMESPACE=your/test-namespace \
YUQUE_SMOKE_ENABLE_WRITE=true \
YUQUE_ALLOW_WRITE=true \
YUQUE_ALLOW_DELETE=true \
YUQUE_DELETE_NAMESPACE_ALLOWLIST=your/test-namespace \
npm run smoke@modelcontextprotocol/sdkfetch or lightweight HTTP clientzod for input validationCONTRIBUTING.mdSECURITY.mddocs/11-weekly-maintenance.mddocs/12-complaint-and-takedown.mdDISCLAIMER.md~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.