asana-automation
Warn
Audited by Socket on Jun 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s Asana automation purpose is coherent, but its trust and data-flow model are weaker than advertised. It relies on a third-party MCP intermediary, uses a possibly discontinued Rube endpoint, and makes setup claims that conflict with current official Composio documentation. Not confirmed malicious, but medium risk due to intermediary credential/data routing and external action capability.
Confidence: 90%Severity: 66%
Audit Metadata