resend

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Malware
MalwareHIGH
agent-email-inbox/SKILL.md

The improved report remains coherent with its stated purpose: it describes a webhook-driven inbound email processing workflow with layered security concepts, integration via the Resend SDK, and guidance for secure deployment. The primary security concerns are standard: secret management, correct webhook signature verification, and careful handling of untrusted email content. No explicit backdoors or exfiltration mechanisms are evident; risks mainly stem from secret leakage, misconfiguration of allowlists, and development-time tooling exposure if not properly managed. Overall security posture is moderate with low malware likelihood; treat as BENIGN with attention to secret handling and robust deployment gating.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 2, 2026, 12:36 PM
Package URL
pkg:socket/skills-sh/DuveSalo%2Fapp%2Fresend%2F@e29c0440d70f035a7f0374b7abaad71eb9735e11