calendly
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose matches Calendly operations, and the npm CLI provenance looks plausible, but the data flow is mediated through ClawLink rather than direct Calendly APIs. That third-party gateway holds OAuth tokens and receives account data/action requests, creating a meaningful trust and credential-forwarding risk that is higher than a standard first-party integration.
Confidence: 88%Severity: 62%
Audit Metadata