coda-automation

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The capability matches Coda automation, and the MCP endpoint appears to be an official Composio/Rube service, so this is not overt malware. But the skill understates credential requirements, routes all Coda access through a third-party intermediary instead of Coda directly, and enables impactful actions like sharing and public publishing; this makes the footprint higher-risk than the description suggests.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Apr 25, 2026, 04:42 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fcoda-automation%2F@5010d1fc30660edc35b5405fa3f7dddbb695d41e