calendly

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches Calendly operations, and the npm CLI provenance looks plausible, but the data flow is mediated through ClawLink rather than direct Calendly APIs. That third-party gateway holds OAuth tokens and receives account data/action requests, creating a meaningful trust and credential-forwarding risk that is higher than a standard first-party integration.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fcalendly%2F@a6c62100a9aefdd760cf33026f693516df9de9461d485c823e11538395988802
Security Audit — socket — calendly