calendly-automation

Warn

Audited by Socket on Jun 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the Calendly functionality matches the stated purpose, but the skill routes all access through Composio/Rube, depends on a discontinued Rube endpoint, and enables consequential external actions. This looks more like a high-trust third-party automation bridge than direct Calendly integration; the main risk is intermediary credential/data handling and operational impact, not confirmed malware.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Jun 25, 2026, 09:50 AM
Package URL
pkg:socket/skills-sh/sitaurs%2Fpbl-ppe-detection%2Fcalendly-automation%2F@90a4f026cda2ec7cbb39d0f20fc2e611e8281c4b38bfec9bb035abe8fdc396e1
Security Audit — socket — calendly-automation