mailbox
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated email purpose broadly matches its capabilities, and its provider URLs are official, but the core trust issue is that all mailbox access and credentials are routed through qwenpawmail-mcp, an external MCP component whose provenance and release integrity are not established in the skill. Because that unverifiable component receives live mailbox credentials and can read/send/delete email, the overall risk is high even without direct evidence of malicious exfiltration.
Confidence: 87%Severity: 84%
Audit Metadata