reply-io-automation
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose and capabilities generally align, and the MCP endpoint appears to be same-org official, so this is not strong evidence of malware. However, it brokers Reply.io authentication and actions through Composio/Rube rather than direct Reply.io APIs, creating meaningful third-party trust, credential-forwarding, and remote-action risk.
Confidence: 84%Severity: 56%
Audit Metadata