sentry-automation

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's Sentry automation purpose is coherent, but its data path is not direct. It relies on a third-party Composio/Rube MCP proxy for both auth and API actions, and the documentation understates this by claiming no API keys are needed. This is not confirmed malware, but it carries meaningful security risk from credential delegation, proxied data flows, and agent-enabled write actions.

Confidence: 90%Severity: 64%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:36 AM
Package URL
pkg:socket/skills-sh/KevinZai%2Fcc-commander%2Fsentry-automation%2F@606036e50afd2cc1760a63a629d7ca3b6a592e20
Security Audit — socket — sentry-automation