venly-automation
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose and capabilities mostly align, and the MCP endpoint appears to be officially operated by Composio/Rube. However, the skill understates credential requirements and routes Venly access through a third-party hosted MCP/intermediary rather than direct official API usage, creating moderate trust and credential-forwarding risk.
Confidence: 84%Severity: 58%
Audit Metadata