productlane-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with Productlane automation and uses same-org Composio/Rube infrastructure, so it is not clearly malicious. However, it routes discovery, auth, and action execution through a third-party MCP intermediary rather than direct Productlane APIs, and the always-search-first workflow lets remote tool metadata influence later actions. Medium risk from intermediary trust, credential delegation, and remote execution shaping.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:37 AM
Package URL
pkg:socket/skills-sh/ranbot-ai%2Fawesome-skills%2Fproductlane-automation%2F@2271b353dfacaa55c862dab11002775b62cdb571