agent-postmark
Warn
Audited by Socket on Jul 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose and requested Postmark capabilities are coherent, but its core trust model is not: it routes sensitive Postmark tokens and message data through unverifiable external CLIs instead of documented direct official API usage. Because an unverifiable binary receives credentials, this is high security risk even without proof of malicious intent.
Confidence: 84%Severity: 86%
Audit Metadata