emailable

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose generally matches its capabilities, and the CLI install path appears legitimate via official npm. The main concern is data-flow integrity: Emailable access is mediated through Membrane, a third-party platform that receives auth context, queries, and results, plus the skill can generate and execute remote actions dynamically. This is not clearly malicious, but it is broader and riskier than a direct Emailable integration.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 11:21 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Femailable%2F@d17f1dfc3896df86ce800485c22bf9a4ee563a01