tapform-automation

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No explicit malicious code or obfuscated payloads are present in this document; the primary supply-chain/security risk is that it requires routing discovery, authentication, and tool execution through a third-party MCP (https://rube.app/mcp). That intermediary will see credentials, session tokens, arguments, and memory unless additional protections are applied. Treat use of this workflow as a moderate to significant supply-chain trust decision: validate the MCP operator, minimize sensitive data sent through it, and require transparency around retention and auditing before using for sensitive workflows.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 17, 2026, 12:13 AM
Package URL
pkg:socket/skills-sh/composiohq%2Fawesome-claude-skills%2Ftapform-automation%2F@f4ec08f23f45ae09e7815f778326b90156cbe6fb