box-automation

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s Box-focused capabilities are largely aligned with its stated purpose, and there is no download-execute or unverifiable binary component. However, all Box access is mediated through Rube/Composio rather than direct Box APIs, creating a third-party data/control path, and the setup instructions appear somewhat inconsistent with official token-based guidance. Overall this is a coherent integration skill with moderate trust and data-flow risk, not clear malware.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:00 AM
Package URL
pkg:socket/skills-sh/aAAaqwq%2FAGI-Super-Team%2Fbox-automation%2F@6bd5d977b08a8637e1b75277ff84ff3a9a1c6a31