gamma-automation
Fail
Audited by Socket on Feb 15, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The artifact is an integration guide that describes routing all Gamma toolkit discovery, authentication, and execution through a third-party MCP (https://rube.app/mcp). No explicit malicious code or obfuscation exists in the provided text, but the architecture concentrates sensitive data and execution authority in the MCP. That introduces a moderate supply-chain risk: if the MCP or any downstream auth/execution endpoints are malicious or compromised, credentials, PII, and tool invocation semantics could be harvested or altered. Recommend vetting the MCP provider, minimizing secrets sent as arguments, and preferring direct, auditable integrations to official Gamma endpoints when possible.
Confidence: 98%
Audit Metadata