trello-automation
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s Trello automation scope is coherent and same-org evidence supports Rube/Composio as an official dependency, but all actions and likely auth handling are mediated through a third-party MCP service rather than direct Trello APIs. That creates moderate data-flow and credential-forwarding risk, plus a documentation inconsistency around 'no API keys needed.'
Confidence: 84%Severity: 56%
Audit Metadata