skill-share
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core capabilities fit the stated purpose, but Slack sharing is routed through the third-party Composio/Rube service, which manages OAuth credentials and receives message data. That makes the data flow less trustworthy than a direct Slack integration, and the dependency appears partly stale because Rube is discontinued. No clear malware indicators or hidden credential theft are shown, but the intermediary auth model and automatic external posting create medium security risk.
Confidence: 86%Severity: 56%
Audit Metadata