parcel-tracking
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The stated purpose is coherent, but the skill's trust boundary is weak because it tells the agent to use whatever Gmail/browser tooling is available. That creates medium risk of email data flowing through third-party MCP providers not identified as official Google services. Courier-link generation itself is benign and proportionate; the main issue is underspecified external tooling and suppressed disclosure of failed scraping.
Confidence: 82%Severity: 57%
Audit Metadata