calendly

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities match Calendly integration, and there is no installer or executable payload. However, all authentication and API traffic are routed through Maton proxy/control domains instead of Calendly's official API, so the skill requires trusting a third-party intermediary with sensitive scheduling data and delegated account access. Risk is medium: coherent purpose, but non-official data flow and transitive skill referral materially increase trust and privacy concerns.

Confidence: 88%Severity: 63%
Audit Metadata
Analyzed At
May 14, 2026, 12:15 AM
Package URL
pkg:socket/skills-sh/CraftOS-dev%2FCraftBot%2Fcalendly%2F@243afc03b29ad4612c078d8feaa19ad77dcbb593
Security Audit — socket — calendly