inbound-cli

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose is coherent for an email-management skill, and `INBOUND_API_KEY` is plausibly the right credential, but the core risk is install/execution trust: I could verify the Inbound brand and API docs, not the specific `inbound-cli` package or the exact CLI commands this skill depends on. Because the skill installs an only partially verified CLI and forwards email-service credentials to it, the security risk is high even without proof of malicious intent.

Confidence: 84%Severity: 80%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/inboundemail%2Finbound%2Finbound-cli%2F@3867373f7d3b9abc0c0426882d4a58c335698886