ElevenLabs Automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities fit its stated ElevenLabs automation purpose, and there is no installer or executable payload. The main concern is data-flow integrity: ElevenLabs credentials and requests are mediated by Composio's hosted MCP gateway (rube.app) rather than going directly to official ElevenLabs API endpoints, with output also delivered via presigned S3 links. That third-party routing is proportionate to a Composio integration but materially increases trust and credential exposure, so this is not benign-direct integration behavior.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/ranbot-ai%2Fawesome-skills%2Felevenlabs-automation%2F@b3262c23626f81dbd34d6024454278ed0979440b