salesforce-automation

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated Salesforce automation purpose matches its capabilities, but its actual trust boundary is a third-party MCP intermediary (Rube/Composio) rather than direct Salesforce API use. The main concern is credential and CRM data routing through that provider, plus slightly overstated setup claims about needing no API keys. This looks more like a legitimate but higher-trust managed integration than malware.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 1, 2026, 07:36 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fsalesforce-automation%2F@1250dc79389a7294f58c4eebc0340521e002fb8b