calendly-automation
Warn
Audited by Socket on Oct 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities mostly match its stated Calendly automation purpose, but it routes sensitive scheduling data and OAuth-backed actions through a third-party hosted MCP service and relies on stale/discontinued Rube setup instructions. This is not confirmed malware, but it carries medium security risk due to remote service trust and real-world action capability.
Confidence: 87%Severity: 53%
Audit Metadata