inbox-providers
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s content is broadly aligned with its purpose as an inbox-provider guide, and most risky behavior is presented as documentation rather than hidden execution. However, it promotes autonomous email actions, references transitive skill/tool installation, and points to weak-hygiene installer patterns (`curl | sh`, unpinned `npx`/`@latest`) that increase trust and operational risk. This looks like a legitimate but security-sensitive documentation skill, not confirmed malware.
Confidence: 87%Severity: 58%
Audit Metadata