agentmail

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is purpose-aligned for agent-owned email and uses mostly coherent official AgentMail infrastructure, so it is not clearly malicious. However, it grants autonomous messaging capability, processes untrusted inbound email, and forwards an API key to an unpinned external MCP package executed via npx, creating meaningful security risk disproportionate to a low-trust automation environment.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:51 PM
Package URL
pkg:socket/skills-sh/NousResearch%2Fhermes-agent%2Fagentmail%2F@c0e39dbd836a51268033fd21119e3262e2179d17