agentmail-cli

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The functionality matches an email-management skill, but install trust is weak: the exact npm CLI package is not clearly verified as an official AgentMail distribution, while the skill passes an API key and sensitive email data into that CLI. The capability set is proportionate to the stated purpose, but the unresolved package provenance and optional endpoint redirection keep risk high.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 25, 2026, 03:49 AM
Package URL
pkg:socket/skills-sh/NeverSight%2Flearn-skills.dev%2Fagentmail-cli%2F@c45ebeeae75ffa8cd5939a9e8010fe32e8302571