mailbox

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated email purpose broadly matches its capabilities, and its provider URLs are official, but the core trust issue is that all mailbox access and credentials are routed through qwenpawmail-mcp, an external MCP component whose provenance and release integrity are not established in the skill. Because that unverifiable component receives live mailbox credentials and can read/send/delete email, the overall risk is high even without direct evidence of malicious exfiltration.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Sep 2, 2026, 09:53 AM
Package URL
pkg:socket/skills-sh/agentscope-ai%2Fqwenpaw%2Fmailbox%2F@38098c1b8d4c73ced26d6292be2f859e724bd803017f68e1abba26f2d2f1db10
Security Audit — socket — mailbox