zoho-mail

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's mail capabilities match its stated purpose, and it does not use risky installers or hidden execution. The main concern is data-flow integrity: all email content and API authentication are routed through Maton-controlled proxy endpoints rather than directly to Zoho, creating a significant intermediary trust and privacy risk; plus it enables autonomous email actions with real-world impact.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Sep 4, 2026, 01:53 PM
Package URL
pkg:socket/skills-sh/craftos-dev%2Fcraftbot%2Fzoho-mail%2F@387e22ed703b592cb9d9d97383e94e40eb655d0bf21b964399f140f4f54ef75d
Security Audit — socket — zoho-mail