zendesk-automation

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s Zendesk automation scope is coherent, but its setup instructions are inconsistent with current official Composio documentation: it points to a discontinued Rube MCP endpoint and claims no API keys are needed, while current Composio Connect docs use different endpoints and auth requirements. Data and auth are brokered through Composio/Rube rather than direct Zendesk APIs, which is proportionate but increases trust requirements. No confirmed malware or covert exfiltration is present, but the stale endpoint, intermediary data flow, and ability to perform destructive/public actions make this a medium-risk skill.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Jul 18, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/rohitg00%2Fbuildwithclaude%2Fzendesk-automation%2F@2368f548db904aa4a4aabb64d283c52df51c9e14e34cb98124e57329cc05f4d6
Security Audit — socket — zendesk-automation