remove-bg-automation
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose is coherent, but it routes Remove Bg operations through Composio's Rube MCP intermediary instead of direct official service APIs and relies on remote schema discovery to drive execution. Same-org provenance keeps this from malicious classification, but third-party mediation, opaque connection handling, and the mismatch with Composio's documented API-key-based setup make the trust and data-flow model medium risk.
Confidence: 83%Severity: 57%
Audit Metadata