agentmail-mcp

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely purpose-aligned for an email MCP integration and uses same-brand domains plus a same-org public repo, which argues against outright malware. However, it forwards an API key through MCP infrastructure, includes unpinned package execution, and grants an AI agent the ability to send real-world emails; this makes it a moderate-to-high security risk despite being plausibly legitimate.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 25, 2026, 03:49 AM
Package URL
pkg:socket/skills-sh/NeverSight%2Flearn-skills.dev%2Fagentmail-mcp%2F@2c0c52b7f90c2eb61b298a1a95217318e67350fb
Security Audit — socket — agentmail-mcp