docusign-automation
Warn
Audited by Socket on Aug 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS overall. The skill’s DocuSign purpose is plausible, but its actual footprint relies on a third-party hosted MCP gateway that brokers OAuth, tool schemas, and sensitive envelope operations instead of direct official DocuSign API use. That data-routing model is higher risk than the stated automation purpose suggests, especially because it can trigger outbound signature requests.
Confidence: 81%Severity: 72%
Audit Metadata