etermin-automation

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No direct malicious code or obfuscation is present in the provided specification. The dominant concern is a supply-chain/trust risk: the skill centralizes authentication and execution through a third-party MCP (rube.app/mcp) without describing token lifecycle, storage, auditability, or least-privilege controls. If the MCP is trustworthy and operates with strong security, this is a manageable integration pattern; if not, it enables credential harvesting, replay of tokens, and potentially harmful bulk operations in Etermin. Recommend: treat the MCP as a high-trust dependency, audit the MCP's security/privacy/retention policies, prefer scoped/ephemeral credentials, require explicit least-privilege scopes for toolkit actions, and log/audit all broker-mediated operations before adoption.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:18 PM
Package URL
pkg:socket/skills-sh/composiohq%2Fawesome-claude-skills%2Fetermin-automation%2F@4361247829b8fa85262422a96a9f15e4291359e3