resend

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose aligns with Resend operations, and the install path uses a normal npm package with same-org evidence, so this is not confirmed malware. However, the integration is mediated by ClawLink rather than direct Resend APIs, meaning credentials and user data/actions flow through a third party, and the skill enables outbound email and other write actions via an unpinned external CLI.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fresend%2F@660664aa94b0e9c385f4a36bb7aaf7819105c997f862ea23c67d68b6554ad528
Security Audit — socket — resend