AGENT LAB: SKILLS

docusign-automation

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill description is functionally correct for DocuSign automation and contains no overt malicious code. Primary security concern is the supply-chain/trust model: the required Rube MCP (https://rube.app/mcp) mediates OAuth and all DocuSign API traffic, concentrating sensitive tokens, document contents, and envelope operations in a third-party service. Before using this toolkit, verify the MCP operator's trustworthiness, request minimal OAuth scopes, confirm token retention and audit policies, and prefer hosting/tooling where you control credential storage or can review the actual toolkit implementation. If those controls cannot be validated, treat this integration as a moderate security risk for sensitive documents.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:10 PM
Package URL
pkg:socket/skills-sh/composiohq%2Fawesome-claude-skills%2Fdocusign-automation%2F@506922921a9ad89993b290910f45c2fb4b627366