dromo-automation

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

There is no evidence of embedded malware or obfuscated code in this document; it is a configuration/usage guide instructing agents to interact with a remote MCP. The primary security concern is architectural: the MCP (https://rube.app/mcp) becomes a central mediator that can receive auth tokens, tool arguments, and execution results. If MCP or returned schemas are malicious or compromised, sensitive data and credentials can be harvested or commands misdirected. Treat the MCP as a high-trust component: verify transport security, limit auth scopes, minimize sensitive data sent, and consider self-hosting or strict vetting before use.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:33 PM
Package URL
pkg:socket/skills-sh/composiohq%2Fawesome-claude-skills%2Fdromo-automation%2F@e6b804d561331d08324df364d44386e2a8abe320