inboxmate-demo
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core MCP/CRM workflow is broadly consistent with building InboxMate demos for psquared, but the skill has medium-high operational risk: it reads local secrets, forwards one credential to an unrelated third-party service, processes untrusted website content while holding write/publish capabilities, and performs real-world actions like publishing demos and creating CRM opportunities with limited confirmation. Not confirmed malware, but risk is elevated and scope is somewhat broader than necessary.
Confidence: 89%Severity: 68%
Audit Metadata