pipedrive-automation

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is functionally coherent with its stated purpose (automating Pipedrive via an MCP-managed pipedrive toolkit). There is no embedded download-and-execute behavior, hardcoded secrets, obfuscated code, or direct evidence of backdoors in the provided text. The principal security concern is architectural: the skill requires and directs users to route Pipedrive OAuth flows and API calls through a third-party MCP (rube.app). That brokered flow means tokens, requests, and CRM data will transit or be stored by the MCP — a legitimate functional choice but a material trust and data-exposure decision. Recommend reviewers confirm the MCP operator's trustworthiness, review where tokens are stored and what scopes are granted, and prefer direct API integrations or explicit minimal-scope OAuth if data confidentiality is required.

Confidence: 70%Severity: 50%
Audit Metadata
Analyzed At
Feb 27, 2026, 09:36 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fpipedrive-automation%2F@72fe556c74cfd6735a2111b9b3fe20c57454e4c5