mixmax
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is internally coherent for a Membrane-based Mixmax integration, and the CLI comes from an official npm package tied to the publisher. However, it routes Mixmax access and credentials through a third-party intermediary CLI/service instead of Mixmax directly, and it enables real-world actions like sending messages. This is not fundamentally incompatible with the stated purpose, but it carries meaningful trust and data-flow risk.
Confidence: 84%Severity: 56%
Audit Metadata