slack-automation

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is a legitimate Slack automation guide that delegates all Slack interactions and OAuth lifecycle to a third-party MCP (https://rube.app/mcp). There is no explicit malicious code in the provided file (no reverse shells, no hard-coded credentials, no obfuscation in the text). The primary security concern is the brokered trust model: OAuth tokens and all message/metadata transit through and are likely stored by the MCP operator, which creates a credential-forwarding / man-in-the-middle risk. Recommend vetting rube.app's security and privacy controls, favoring direct integrations when possible, applying least-privilege scopes, and auditing MCP activity before using in sensitive workspaces.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/aAAaqwq%2FAGI-Super-Skills%2Fslack-automation%2F@3ef193c2ad4da164b4d68ceda7dc81908ea77958