customer-winback

Warn

Audited by Socket on Jul 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The business workflow is coherent, but the skill routes sensitive Gorgias, HubSpot, and Gmail access through Composio rather than official service APIs. Because a third-party CLI and managed auth layer sit between the agent and the services, this creates meaningful credential-forwarding and customer-data exposure risk despite a largely legitimate stated purpose.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Jul 1, 2026, 08:14 PM
Package URL
pkg:socket/skills-sh/composio-community%2Fsupport-skills%2Fcustomer-winback%2F@0f024f21b254d269c71a19efae3edf5727d20bdc1bc5292c78fc9a8993e437f0
Security Audit — socket — customer-winback