bidsketch-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the MCP endpoint appears to be official Composio infrastructure. The main concern is data-flow integrity: Bidsketch operations and authenticated access are funneled through Composio/Rube rather than directly to Bidsketch, which introduces intermediary visibility and broader trust requirements. This is not confirmed malware, but it carries moderate security risk due to third-party mediation of account actions and data.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/ranbot-ai%2Fawesome-skills%2Fbidsketch-automation%2F@aaf84e98dd87135169259bd146328255032c23af