smartrmail

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated purpose, and the CLI comes from an official npm package rather than an obviously untrusted source. However, the core integration depends on Membrane as an intermediary for authentication, credential refresh, and API proxying, so SmartrMail data and account access flow through a third party instead of directly to official SmartrMail endpoints. That is a proportionate but higher-trust architecture, making this more concerning than a direct API skill but not clearly malicious.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:39 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsmartrmail%2F@b17f05b0c1806bdc3b10cc2dc30fb3aa81873af0