docusign-automation

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS overall. The skill’s DocuSign purpose is plausible, but its actual footprint relies on a third-party hosted MCP gateway that brokers OAuth, tool schemas, and sensitive envelope operations instead of direct official DocuSign API use. That data-routing model is higher risk than the stated automation purpose suggests, especially because it can trigger outbound signature requests.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Aug 13, 2026, 03:35 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fdocusign-automation%2F@5a52bb69d1bf47170857da8bc8d8642dc18b21348db11c5c260d8fe5789c68dc
Security Audit — socket — docusign-automation