agentmail

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The AgentMail skill presents a coherent, purpose-aligned tool for programmatic email inbox management via a REST API. Its footprint (API token usage, curl-based interactions, webhook/event flows) matches the stated objective and does not introduce extraneous capabilities like code execution or system access. Security concerns are limited to standard API token handling and endpoint trust for webhooks; these are typical for integration tooling and can be mitigated with proper secret management and endpoint vetting. Overall, the skill is BENIGN with MEDIUM securityRisk due to credential exposure potential in examples/logs, and no explicit unverifiable binaries or data exfiltration patterns detected.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fvm0-skills%2Fagentmail%2F@275a9081314ffd5fd621acd983b72fe64b4e57c6