ethermail

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core EtherMail site usage is plausible, but the skill’s main login path depends on installing a separate third-party skill and giving it a wallet private key for signing. That transitive install plus credential forwarding is disproportionate to a simple email-access skill and materially raises supply-chain and credential-theft risk, even without proof of outright malware.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
May 20, 2026, 04:44 PM
Package URL
pkg:socket/skills-sh/dAAAb%2Fagent-skills%2Fethermail%2F@4ed5829d031a680ef4a9c66c89e324c049b68b54
Security Audit — socket — ethermail