nylas
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is internally coherent for a Membrane-published Nylas integration and uses an official npm-distributed CLI, but it routes all authentication and API access through Membrane rather than directly to Nylas. That third-party credential and data mediation is proportionate to the product design yet increases trust and privacy risk, so this is best classified as medium-risk rather than benign or malicious.
Confidence: 88%Severity: 58%
Audit Metadata