docusign-automation
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The DocuSign automation scope is coherent, and requested capabilities match the stated purpose, but the skill’s trust path is outdated: it relies on a discontinued third-party MCP endpoint (rube.app) instead of current official Composio infrastructure. Data appears to flow to an expected intermediary for OAuth and DocuSign actions, not an obvious exfiltration service, so this is not confirmed malware; the main issue is stale remote dependency trust and delegated credential handling through the MCP layer.
Confidence: 89%Severity: 56%
Audit Metadata