mandrill

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose broadly matches an email-service integration, and the CLI comes from an official registry under the same vendor. The main concern is data-flow integrity: Mandrill access is mediated through Membrane's account system and proxy rather than direct calls to Mandrill's official API, creating a third-party interception point for data and auth handling. This is not confirmed malware, but it is a medium-risk integration pattern.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 8, 2026, 08:31 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmandrill%2F@85901a5bd932169b60beb92c3da75c3dedb65942
Security Audit — socket — mandrill