ElevenLabs Automation
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's capabilities fit its stated ElevenLabs automation purpose, and there is no installer or executable payload. The main concern is data-flow integrity: ElevenLabs credentials and requests are mediated by Composio's hosted MCP gateway (rube.app) rather than going directly to official ElevenLabs API endpoints, with output also delivered via presigned S3 links. That third-party routing is proportionate to a Composio integration but materially increases trust and credential exposure, so this is not benign-direct integration behavior.
Confidence: 85%Severity: 56%
Audit Metadata