basecamp-automation

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s Basecamp automation purpose is coherent, but it routes sensitive Basecamp operations and OAuth-backed access through Composio/Rube instead of official Basecamp endpoints. Same-org evidence reduces malware concern, yet the third-party mediation, inconsistent auth claims, and ability to post content or change project membership make this a high-impact, medium-to-high security risk skill.

Confidence: 84%Severity: 71%
Audit Metadata
Analyzed At
Apr 18, 2026, 03:49 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fbasecamp-automation%2F@fd4542233f6f630c29efd1b996c86da4fb6d73b3