trello-automation

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's Trello automation purpose matches its capabilities, but all access and auth are routed through the third-party Rube/Composio MCP service instead of direct Trello APIs. That intermediary model creates medium risk around data handling and autonomous external actions, though there is no evidence of overt malware or unrelated credential theft.

Confidence: 81%Severity: 63%
Audit Metadata
Analyzed At
Apr 29, 2026, 12:45 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Ftrello-automation%2F@90e66bfb1ac154fbe007f6c9d41b87a18452611b