slack-automation

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s Slack capabilities fit its stated purpose, and the endpoint appears to be an official Composio/Rube service, so this is not outright malware. However, it routes Slack authentication and all workspace operations through a third-party hosted MCP layer and enables autonomous external messaging actions; combined with outdated 'no API keys needed' setup guidance, this makes the skill medium-high risk.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Apr 14, 2026, 11:48 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fslack-automation%2F@c2a6eddbea9d8a68083b619f3d2624169b8311ed