migma

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Migma CLI skill appears coherently aligned with its stated purpose: it authenticates with an API key, generates and validates emails, manages contacts, campaigns, domains, and webhooks, and supports exports. The data flows primarily between the local CLI and official Migma API endpoints, with user-configured webhooks as external sinks. There are no obvious unverifiable binaries or suspicious data exfiltration paths in the provided description. The main security considerations concern proper handling and protection of the MIGMA_API_KEY, secure local storage, and ensuring webhook endpoints are trusted. Overall, the footprint is benign and proportionate to the described email automation purpose, with a moderate but acceptable risk profile given external webhook data flows.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:33 PM
Package URL
pkg:socket/skills-sh/migmaai%2Fmigma-skills%2Fmigma%2F@6c258113dd9f1df46ebd533e9e290c3b812ab695