e-mail-agent-cli

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The mailbox capabilities mostly align with the stated purpose and the OAuth flow is comparatively well-scoped, but the install/execution chain is not fully verifiable from the provided content: the skill depends on a separate public CLI plus a secondary payload install, and the actual publisher relationship for e-mail-agent-cli is not established here. The skill also enables autonomous email actions with user-impacting consequences and can export reusable auth data to disk. Without stronger provenance evidence for the CLI and payload, this should be treated as medium risk rather than benign.

Confidence: 79%Severity: 59%
Audit Metadata
Analyzed At
Apr 11, 2026, 03:10 PM
Package URL
pkg:socket/skills-sh/codecell-germany%2Fe-mail-agent-skill%2Fe-mail-agent-cli%2F@5d3ba7e278ecc90b8b260da68047a8cbdd0e1b9e