v0-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated purpose, and the publisher/source relationship is consistent with official Composio docs. The main concern is data-flow integrity: V0 actions and auth are mediated through Composio's hosted Rube MCP instead of direct first-party V0 endpoints, creating a third-party credential/action trust boundary. This is not clearly malicious, but it is a meaningful security and privacy risk for an automation skill.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:09 AM
Package URL
pkg:socket/skills-sh/ranbot-ai%2Fawesome-skills%2Fv0-automation%2F@5cd2487ea8011a371a1abf9a10162bacfb472e95