booking-notify

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core notification purpose is plausible, but the actual footprint is broader than necessary. The main concerns are reliance on an unverifiable custom binary from another plugin, transitive trust in calcom-commander, and routing optional notification flows through a custom Cloud Run relay. Official Telegram/Pushover use is normal, but the local executable and intermediary relay make the overall skill high-risk rather than benign.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
May 11, 2026, 01:41 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fbooking-notify%2F@47809c6999d70d162b6bbbe018135c6a8736b04f