gmail-multi-inbox

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and core capabilities are coherent, and its Google Apps Script/Gmail API usage aligns with documented Google functionality. The main risk is data-flow and trust: inbox scanning depends on an unspecified third-party Gmail MCP connector with no verifiable provenance, so potentially sensitive email data may transit an unvetted intermediary. This is not confirmed malware, but it is a medium-risk skill because a sensitive mailbox integration is routed through an unverified connector.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Mar 26, 2026, 09:17 PM
Package URL
pkg:socket/skills-sh/apocohq%2Fskills%2Fgmail-multi-inbox%2F@af870b44e29a1735aed7c68b0a530baed6a26c67