slack-automation

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s Slack capabilities fit its stated purpose, and the endpoint appears to be an official Composio/Rube service, so this is not outright malware. However, it routes Slack authentication and all workspace operations through a third-party hosted MCP layer and enables autonomous external messaging actions; combined with outdated 'no API keys needed' setup guidance, this makes the skill medium-high risk.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
May 9, 2026, 03:53 AM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fslack-automation%2F@70e9901b8d137aa60c09ad553760c294e1903f2b