calendly-automation

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's Calendly capabilities fit its stated purpose, but its trust boundary is broader than expected because authentication and API operations are routed through the third-party Rube/Composio MCP instead of Calendly's first-party MCP/API path. The main risk is third-party credential/data handling plus live administrative actions, not clear malware or deception.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 11:57 AM
Package URL
pkg:socket/skills-sh/diegosouzapw%2Fawesome-omni-skill%2Fcalendly-automation%2F@a9753211b13f157ea5f3073907a4f43dae3c298b
Security Audit — socket — calendly-automation