docusign-automation

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The DocuSign automation scope is coherent, and requested capabilities match the stated purpose, but the skill’s trust path is outdated: it relies on a discontinued third-party MCP endpoint (rube.app) instead of current official Composio infrastructure. Data appears to flow to an expected intermediary for OAuth and DocuSign actions, not an obvious exfiltration service, so this is not confirmed malware; the main issue is stale remote dependency trust and delegated credential handling through the MCP layer.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Sep 4, 2026, 03:06 PM
Package URL
pkg:socket/skills-sh/new-career-begin%2Fqueryweaver%2Fdocusign-automation%2F@b2f14e6834510422158f856de84d60388eb15c42e097475c99dbf9eca615b749
Security Audit — socket — docusign-automation