agent-postmark

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and requested Postmark capabilities are coherent, but its core trust model is not: it routes sensitive Postmark tokens and message data through unverifiable external CLIs instead of documented direct official API usage. Because an unverifiable binary receives credentials, this is high security risk even without proof of malicious intent.

Confidence: 84%Severity: 86%
Audit Metadata
Analyzed At
Jul 16, 2026, 01:20 PM
Package URL
pkg:socket/skills-sh/shhac%2Fagent-skills%2Fagent-postmark%2F@542b22b62e35d5ded14e145c9a56d9a7fa8ce8aa71b9ccff9ec6fc14645c45b2
Security Audit — socket — agent-postmark