calcom-access

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's Cal.com purpose is plausible, but it routes sensitive access through a custom local marketplace CLI with unclear provenance and a build step that pulls dependencies before use. Credential scope is roughly aligned to task, yet the hidden-plugin trust chain and self-modifying behavior raise medium-high security risk even without direct evidence of malware.

Confidence: 81%Severity: 68%
Audit Metadata
Analyzed At
May 11, 2026, 01:42 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fcalcom-access%2F@72d87b509baffdaf1bc5b632acac144906bd4c89