box-automation

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill is internally consistent for Box automation, but it routes sensitive Box operations and auth through a third-party MCP/Composio service instead of direct Box APIs. That makes it a coherent integration skill with notable trust and data-flow risk, not confirmed malware.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:46 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fbox-automation%2F@2ccd2e99e2f29e29fad3a1cbf30cb0414f4eea02