bidsketch-automation
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose and capabilities mostly align, and the MCP endpoint appears to be official Composio infrastructure. The main concern is data-flow integrity: Bidsketch operations and authenticated access are funneled through Composio/Rube rather than directly to Bidsketch, which introduces intermediary visibility and broader trust requirements. This is not confirmed malware, but it carries moderate security risk due to third-party mediation of account actions and data.
Confidence: 85%Severity: 52%
Audit Metadata