attio

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Attio CRM integration described is coherent with a legitimate CRM automation capability. It uses standard API-based authentication (ATTIO_API_KEY in environment), direct network calls to official Attio endpoints, and supports proportionate CRM operations (records, notes, tasks, pipelines). There are no evident supply-chain, credential-forwarding, or data-exfiltration patterns. Recommend standard security best practices: protect API keys, minimize scopes, ensure TLS, log redaction, and monitor API activity. Overall risk is LOW to MEDIUM (benign with normal credential handling) given the described scope and data flows.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:32 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fattio%2F@209c763e043f16b2c22bbb1607bed5646f3fc789