agent-mail

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/integrate_claude_code.sh

This appears to be a legitimate integration/setup script for configuring Claude Code MCP and installing execution hooks for `mcp_agent_mail`. No clear exfiltration, backdoor, or destructive behavior is present in the provided fragment. The most concerning issue is the use of `eval` on shell `export` statements generated by Python, which can become a command-injection sink if endpoint settings are attacker-controlled. Overall: low likelihood of intentional malware, but moderate supply-chain/security risk due to dynamic evaluation and creation of executable hooks and token-bearing configs.

Confidence: 66%Severity: 55%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:12 PM
Package URL
pkg:socket/skills-sh/dicklesworthstone%2Fmcp_agent_mail%2Fagent-mail%2F@1b888b4d1c18fefa803fcf014494c441c2eca91a