mailcoach
Warn
Audited by Socket on May 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly coherent for a Membrane-based Mailcoach integration and uses an official npm-distributed CLI, so it is not clearly malicious. However, it routes authentication and data access through Membrane rather than Mailcoach directly, forwards account authority to a third-party service, and allows dynamic server-side action creation, which makes the trust and data-flow footprint materially larger than a simple Mailcoach connector.
Confidence: 84%Severity: 58%
Audit Metadata