Uploadcare Automation

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The manifest describes a benign, well-scoped Uploadcare automation toolkit. There is no direct evidence of malicious code or intentionally obfuscated behavior in the provided document. However, the required use of a third-party MCP (Composio/Rube) to broker API calls and hold credentials introduces a notable supply-chain and privacy risk because the manifest lacks details on credential storage, access control, and data retention. If the MCP is untrusted or compromised, API keys, file metadata, and temporary download links could be exposed or abused. Recommend validating the MCP provider's security posture, using least-privilege and short-lived credentials, enabling Uploadcare audit logging, and minimizing sensitive uploads involved with this toolkit.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 17, 2026, 12:36 AM
Package URL
pkg:socket/skills-sh/composiohq%2Fawesome-claude-skills%2Fuploadcare-automation%2F@aaecda30aff1e1d3cdda6d864a3dc947402f3094