calendly-automation
Warn
Audited by Socket on May 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's Calendly capabilities fit its stated purpose, but its trust boundary is broader than expected because authentication and API operations are routed through the third-party Rube/Composio MCP instead of Calendly's first-party MCP/API path. The main risk is third-party credential/data handling plus live administrative actions, not clear malware or deception.
Confidence: 100%Severity: 60%
Audit Metadata