trello-automation

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated Trello automation purpose is plausible, but the setup and data flows are inconsistent with current official Composio documentation. The main risk is third-party interception/mediation of Trello auth and data via a deprecated Rube MCP endpoint, plus misleading setup claims ('no API keys needed'). No confirmed malware, exploit code, or load-time execution is present.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Jun 19, 2026, 05:06 PM
Package URL
pkg:socket/skills-sh/ncdevshiv%2FNC-skills-mcp%2Ftrello-automation%2F@8d28f990c702ed6ef7d5f6176a7d700703ae133e2fb338f56f966ab0efd527ec
Security Audit — socket — trello-automation