emelia-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are broadly aligned, and the endpoint appears to be official Composio infrastructure rather than a random third party. However, it acts as a gateway skill: Emelia authentication and all tool execution are mediated through Rube/Composio instead of direct Emelia APIs, so user data and credentials depend on that intermediary's trust model. There is no opaque binary download here, which lowers supply-chain concern, but the remote MCP can dynamically expose actions and schemas, creating moderate execution and data-flow risk.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:37 AM
Package URL
pkg:socket/skills-sh/ranbot-ai%2Fawesome-skills%2Femelia-automation%2F@471019d8ffbf91a826f110122ff2cb3818ffd1df