Mailchimp Automation

Warn

Audited by Socket on Jun 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The Mailchimp-focused capabilities are coherent, but the skill’s operational footprint relies on an undocumented MCP intermediary that does not appear to be official Mailchimp infrastructure. That creates medium-high supply-chain and credential-forwarding risk, especially because Mailchimp keys are high-privilege and campaign sends/audience changes have real-world effects.

Confidence: 85%Severity: 79%
Audit Metadata
Analyzed At
Jun 3, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/claude-office-skills%2Fskills-hub%2Fmailchimp-automation%2F@7ec3e78d627d754c269f34d34bcccad61afb9964
Security Audit — socket — Mailchimp Automation