freshservice-automation

Warn

Audited by Socket on Oct 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's Freshservice automation purpose is coherent, but its trust model is dated and somewhat misleading. It routes actions and credentials through a legacy Composio/Rube MCP proxy, uses deprecated tool naming, and says no API keys are needed even though Freshservice authentication still occurs server-side via Composio. No direct malware indicators or rogue exfiltration endpoints are shown, but the remote dependency and mutable hosted tool surface make this a medium-risk skill.

Confidence: 88%Severity: 52%
Audit Metadata
Analyzed At
Oct 8, 2026, 08:58 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Ffreshservice-automation%2F@3be2d275d287fee64dd283fa8e8588ca5a38d880ab7f27022a2290e002a3575e