calcom-access

Warn

Audited by Socket on Sep 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core workflow is broadly consistent with a Cal.com integration and uses plausible tools (1Password CLI, Cal.com API), but the skill relies on an unreviewable local CLI that likely handles secrets, and its reference docs pull in a broader secret environment than the stated task needs. No clear exfiltration endpoint or confirmed malware appears, but install/credential trust is incomplete and scope is somewhat disproportionate.

Confidence: 82%Severity: 53%
Audit Metadata
Analyzed At
Sep 28, 2026, 12:42 PM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fcalcom-access%2F@0ed36a14a1c1ceb6becfb9513898b00e2aad769ea464ad1861fd0ccd833d30ee
Security Audit — socket — calcom-access