demio-automation

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This manifest is a benign orchestration specification that delegates Demio interactions to an external MCP proxy. The principal security concern is architectural: sensitive data and authentication are centralized at the MCP operator, creating a potential credential and data-exfiltration vector if the MCP is not fully trusted. There is no evidence of in-file obfuscation, hard-coded secrets, or active malware, but operational caution is required: validate the MCP provider, audit auth redirect endpoints and scopes, and monitor/limit executed tool actions.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:00 PM
Package URL
pkg:socket/skills-sh/composiohq%2Fawesome-claude-skills%2Fdemio-automation%2F@2574d56781100085d92572faee466e6cbe1383de