rafflys-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent as a Composio/Rube-based Rafflys automation guide, and its endpoint appears officially documented by the same org ecosystem. However, it routes actions and likely credentials through a third-party MCP/service layer instead of direct Rafflys APIs, and the setup wording understates the real authentication/trust model. Medium risk from delegated execution and indirect data flow, but not enough evidence for malware.

Confidence: 84%Severity: 54%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/ranbot-ai%2Fawesome-skills%2Frafflys-automation%2F@7225a723df39f76739a24aef6155f3c24beb5c84