trello-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's Trello automation purpose matches its capabilities, and the MCP endpoint appears to be the official same-org Rube/Composio service. The main concern is architectural: all Trello access is mediated by a third-party remote MCP gateway rather than Trello's official API directly, increasing data exposure and trust requirements; this is medium risk but not evidence of malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Ftrello-automation%2F@85b31c2e0cc82096fbfc9a65c5cc1ccaaa9b07b3