mailchimp

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's Mailchimp-management purpose is coherent, and there is no binary install or overt command-execution malware. However, all authentication and Mailchimp data/actions are funneled through Maton-controlled proxy domains rather than Mailchimp's official API, creating a man-in-the-middle trust model that is disproportionate for a normal API integration. That third-party gateway can observe the user's Maton API key, Mailchimp OAuth-backed requests, subscriber data, reports, and campaign actions, so the main risk is credential/data routing through an intermediary rather than command injection.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Sep 4, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/craftos-dev%2Fcraftbot%2Fmailchimp%2F@490bd3bab77fd9e9fde20189bca6dcc00f2aa14b6f1b7a71f20e5ea2b6ad2bb8
Security Audit — socket — mailchimp