sendgrid

Warn

Audited by Socket on Feb 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected No direct malware or obfuscated malicious code found in the provided documentation. The dominant security concern is architectural: this integration proxies all API calls and user data through Maton-managed services, requiring users to trust Maton with their MATON_API_KEY and any OAuth tokens obtained via the connect URL. That pattern centralizes sensitive data and privileges and raises supply-chain risk (token/credential theft, data exposure, unauthorized email sending) if Maton is compromised or misbehaves. Recommend: only use this gateway when Maton is a trusted operator and after reviewing Maton's token-scoping, retention, auditing, and revocation policies; if the threat model demands direct control over credentials or minimal third-party exposure, use direct SendGrid OAuth/API keys instead. LLM verification: The document is legitimate documentation for a SendGrid integration mediated by Maton. There is no malicious code in the file itself. The dominant security concern is supply-chain/privacy: MATON_API_KEY and OAuth tokens are intentionally routed through Maton’s infrastructure, making Maton a high-value interception/storage point for sensitive email content, contacts, and API keys. Use this skill only if you trust Maton and have validated their security controls; otherwise use direct api.sendgrid.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 23, 2026, 08:49 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fsendgrid%2F@b553e67a8785317c4b30d113740cd03a4036c1c8