bamboohr-automation

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities match its stated BambooHR automation purpose, and the MCP endpoint appears to be an official Composio/Rube service rather than a random installer. However, sensitive HR data and auth flow are routed through a third-party intermediary instead of directly to BambooHR, and the setup instructions understate current authentication requirements. This is not confirmed malware, but it carries meaningful privacy and service-trust risk disproportionate to a simple 'no keys needed' setup claim.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 18, 2026, 03:48 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fbamboohr-automation%2F@1fd71c78c1840cfd286b7f73c700a44da15af4b6