Lemon Squeezy Automation
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's capabilities fit its Lemon Squeezy management purpose, but credentials and business data are routed through a third-party MCP service (Composio/Rube) instead of directly to Lemon Squeezy. This is not strong evidence of malware, yet the intermediary credential and data flow creates meaningful trust and privacy risk.
Confidence: 85%Severity: 64%
Audit Metadata