sendgrid-automation
Warn
Audited by Socket on Apr 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's capabilities match its stated SendGrid automation purpose, and the Rube/Composio dependency appears same-org legitimate rather than a random installer. The main risk is architectural: SendGrid auth and data flow through a third-party managed MCP gateway, and the skill enables high-impact outbound email and contact-management actions without strong approval guardrails. Not malicious, but medium-high risk due to delegated credential/data handling and autonomous external actions.
Confidence: 86%Severity: 68%
Audit Metadata