LaunchDarkly Automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated LaunchDarkly automation purpose, and the Composio/Rube endpoint appears to be same-org documented infrastructure rather than an obvious rogue installer. The main risk is architectural: LaunchDarkly credentials and management actions are routed through a third-party MCP intermediary, and the skill can create or delete operational trigger workflows with real-world effect. This is not confirmed malware, but it carries medium security risk and should be used only with clear user approval and scoped credentials.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 29, 2026, 04:36 AM
Package URL
pkg:socket/skills-sh/ranbot-ai%2Fawesome-skills%2Flaunchdarkly-automation%2F@4237ffad13e75ca4809dbba38a0c1bac604e1916