pp-agentmail
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose largely matches its capabilities, but it requires a non-vendor wrapper CLI that handles AgentMail credentials and can perform outbound email/webhook actions. Install provenance is partially verifiable and same-publisher, so this is not confirmed malware, but the combination of third-party credential forwarding, unpinned fallback installs, and silent background learning actions makes the skill higher-risk than a normal documentation or API guide skill.
Confidence: 88%Severity: 61%
Audit Metadata