postmark

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities fit its stated Postmark purpose, and the CLI install path appears to be an official vendor/npm route, so this is not clearly malicious. However, all Postmark access and credentials are routed through Membrane rather than Postmark's native API, and the skill enables outbound email actions with real-world consequences; combined with an unpinned global CLI install, this makes the overall risk medium.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpostmark%2F@0fc6568dc2083414fb3ff3980602e64ef3dee7f3