asana-automation

Warn

Audited by Socket on Jun 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s Asana automation purpose is coherent, but its trust and data-flow model are weaker than advertised. It relies on a third-party MCP intermediary, uses a possibly discontinued Rube endpoint, and makes setup claims that conflict with current official Composio documentation. Not confirmed malicious, but medium risk due to intermediary credential/data routing and external action capability.

Confidence: 90%Severity: 66%
Audit Metadata
Analyzed At
Jun 22, 2026, 09:04 PM
Package URL
pkg:socket/skills-sh/sitaurs%2Fpbl-ppe-detection%2Fasana-automation%2F@22f0449521c409e89c184a22ccb2792a0773e8fd2b43e24f66bc8276dd1bf1bb
Security Audit — socket — asana-automation