Asana Automation

Warn

Audited by Socket on Jun 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches project-management automation, and there are no explicit malicious commands, downloads, or exfiltration endpoints. However, the core execution dependency `project-mcp` is an undocumented, unverifiable intermediary with unclear provenance and unclear data routing, which is disproportionate for a skill that could otherwise describe direct official Asana API use. Main risk is trust and opacity, not confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Jun 3, 2026, 02:52 PM
Package URL
pkg:socket/skills-sh/claude-office-skills%2Fskills-hub%2Fasana-automation%2F@73a4c19f6bfd7994975c6cad59d5febceed5acdf
Security Audit — socket — Asana Automation