close-automation

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's CRM capabilities broadly match its stated purpose, and it does not include local code execution, credential-file reading, or obvious malware behavior. However, all Close data and actions are mediated through a third-party hosted MCP endpoint (Rube/Composio) instead of direct official API usage, which creates meaningful data-flow and trust risk, especially because the skill supports outbound SMS and destructive CRM actions. This looks coherent as a CRM automation skill, but the intermediary service model raises medium security concern.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Jul 18, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/rohitg00%2Fbuildwithclaude%2Fclose-automation%2F@cd1f3d8d497e3bbe19ef0af6e9b4aaf78c241da4c6f3cacca3562bffa2b6680e
Security Audit — socket — close-automation