emailable

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align, and it uses an official npm-distributed CLI rather than a raw binary. However, it introduces a third-party trust boundary by requiring a Membrane account and routing Emailable authentication and API traffic through Membrane’s platform/proxy instead of direct Emailable endpoints; combined with a mutable global `@latest` install, this creates moderate supply-chain and data-flow risk without strong signs of outright malware.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 05:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Femailable%2F@1fe7648e588449471043fe3ee75b2840fce9c99f
Security Audit — socket — emailable