calendly-automation

Warn

Audited by Socket on Oct 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated Calendly automation purpose, but it routes sensitive scheduling data and OAuth-backed actions through a third-party hosted MCP service and relies on stale/discontinued Rube setup instructions. This is not confirmed malware, but it carries medium security risk due to remote service trust and real-world action capability.

Confidence: 87%Severity: 53%
Audit Metadata
Analyzed At
Oct 8, 2026, 08:57 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fcalendly-automation%2F@5033cfcd894749ece578abc796cac723dbf135a51cb64612aae5ddec3052c62b