espocrm-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly aligned with its stated EspoCRM automation purpose and uses same-ecosystem Composio/Rube infrastructure, but it relies on a third-party hosted MCP intermediary for tool discovery, authentication, and execution. The main concerns are credential/API mediation through Composio, mutable remote-service trust, and inconsistent setup claims about authentication. This looks more like a medium-risk hosted integration than malware.

Confidence: 82%Severity: 54%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:39 AM
Package URL
pkg:socket/skills-sh/ranbot-ai%2Fawesome-skills%2Fespocrm-automation%2F@9f0c14225ae6c1f3b238f9999dface3dffc081cb