keyid-agent-kit-mcp

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN for stated purpose but HIGH-RISK in operation. The skill is internally consistent: it installs a KeyID package from npm and routes email functions to KeyID.ai as advertised. The main security issue is proportionality of autonomous outbound email actions and processing of untrusted inbound email, which can let an agent send messages or act on prompt-injection content without explicit approval.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 19, 2026, 06:31 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fkeyid-agent-kit-mcp%2F@9e42c5c700f6b4361c6953eb699df1c2a426fe0b