booking-config
Warn
Audited by Socket on May 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose matches Cal.com administration, and official traffic goes to Cal.com plus 1Password for secret retrieval, but the skill relies on an unverifiable local CLI binary, forwards booking events to an external relay, and handles API keys in a less-safe way. The footprint is mostly coherent, yet install trust and outbound data routing are broader than necessary for a straightforward booking-config skill.
Confidence: 87%Severity: 82%
Audit Metadata