zendesk-automation
Warn
Audited by Socket on Jul 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s Zendesk automation scope is coherent, but its setup instructions are inconsistent with current official Composio documentation: it points to a discontinued Rube MCP endpoint and claims no API keys are needed, while current Composio Connect docs use different endpoints and auth requirements. Data and auth are brokered through Composio/Rube rather than direct Zendesk APIs, which is proportionate but increases trust requirements. No confirmed malware or covert exfiltration is present, but the stale endpoint, intermediary data flow, and ability to perform destructive/public actions make this a medium-risk skill.
Confidence: 90%Severity: 58%
Audit Metadata