quickmailio

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent and uses a normal npm-installed CLI, but it routes QuickMail access and authentication through Membrane rather than the official QuickMail API directly. That third-party credential and data mediation is the primary risk; there is no strong evidence of malware or hidden exfiltration beyond the disclosed proxy design.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 07:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fquickmailio%2F@e40459b70e0e2a5de102da823d5bc04505a89e5b