elastic-email

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent, but it mediates all Elastic Email access through Membrane instead of the official service, creating meaningful third-party credential and data-flow risk. Install trust is moderate rather than severe because the CLI comes from npm and matches the publisher, but the indirect API path and ability to send emails and modify remote resources make this a medium-risk integration skill.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Apr 29, 2026, 12:46 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Felastic-email%2F@e9d2cd9affe785006bdf27152624f23e1b6d41e9
Security Audit — socket — elastic-email