recruitee-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are broadly aligned for Recruitee automation, and the MCP endpoint appears to be an official same-org Composio/Rube service rather than a random host. However, all automation and authentication are mediated through a third-party MCP gateway (rube.app/Composio) instead of direct Recruitee API usage, so recruiter data and action authority flow through an intermediary. This is not confirmed malware, but it creates meaningful trust, privacy, and autonomous-action risk beyond a simple documentation skill.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:44 AM
Package URL
pkg:socket/skills-sh/ranbot-ai%2Fawesome-skills%2Frecruitee-automation%2F@02e5540333b0cab27bef6b284780ec965474f3f0