analyse-inboxmate
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. As a documentation skill it is mostly coherent, but it goes beyond passive reference by telling the agent exactly where local secrets live and by exposing multi-system admin workflows that can send email, run SQL, and modify demos. Data stays on same-org infrastructure and there is no install-chain evidence, so this is not confirmed malware, but the credential scope and actionability are disproportionate for a simple ecosystem reference.
Confidence: 87%Severity: 63%
Audit Metadata