mailcoach

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's Mailcoach purpose is plausible, and the Membrane CLI appears to be an official package, but the actual integration is mediated through Membrane's account, CLI, and proxy rather than direct Mailcoach APIs. That makes credential and data flow broader than necessary for a Mailcoach skill and introduces medium risk, especially with mutable `npx @latest` execution.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmailcoach%2F@af0da553207a0e3b857087bd575aac715eee3c20