mailcoach

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent for a Membrane-based Mailcoach integration and uses an official npm-distributed CLI, so it is not clearly malicious. However, it routes authentication and data access through Membrane rather than Mailcoach directly, forwards account authority to a third-party service, and allows dynamic server-side action creation, which makes the trust and data-flow footprint materially larger than a simple Mailcoach connector.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 6, 2026, 03:22 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmailcoach%2F@20660a9c06e79340dfb9f715cad82d75dccb0cf6