box-automation

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Report 2 provides a more credible and actionable assessment but remains medium risk due to external MCP trust boundary and OAuth handling. The integration is not inherently malicious, but the reliance on an external MCP for tool schemas and the potential cross-service parameter mismatches warrant careful secure design, explicit credential handling, and auditable workflows before production use.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Feb 27, 2026, 09:34 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fbox-automation%2F@d63ec590a888970d987997343a4c57dbc8a9b21b