convertkit-automation

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's ConvertKit operations are coherent, and the Rube MCP endpoint appears officially tied to Composio, so this is not confirmed malware. However, all account data and actions are mediated through a third-party hosted MCP/OAuth service rather than direct Kit APIs, and the skill enables destructive real-world actions; that makes the data flow and trust model moderately risky.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 17, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fconvertkit-automation%2F@2188fa04385973ea4ed80ad5f41381ea4a2290d2