sendgrid-automation
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is broadly aligned with its stated SendGrid automation purpose, and the referenced MCP service appears to be an official Composio/Rube endpoint rather than an obvious rogue installer. The main risk is architectural: SendGrid credentials and account actions are routed through a third-party hosted MCP intermediary, and the skill enables sending emails and modifying contacts on the user's behalf. That makes it medium risk and somewhat suspicious from a data-flow and autonomy perspective, but not malicious on the evidence provided.
Confidence: 86%Severity: 58%
Audit Metadata