calcom-access
Warn
Audited by Socket on Sep 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core workflow is broadly consistent with a Cal.com integration and uses plausible tools (1Password CLI, Cal.com API), but the skill relies on an unreviewable local CLI that likely handles secrets, and its reference docs pull in a broader secret environment than the stated task needs. No clear exfiltration endpoint or confirmed malware appears, but install/credential trust is incomplete and scope is somewhat disproportionate.
Confidence: 82%Severity: 53%
Audit Metadata