agent-postmark
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS due to install-trust uncertainty, not because of obviously malicious behavior. The skill’s purpose, capabilities, and token scoping are largely coherent and proportionate for Postmark support triage, and its guidance reduces direct credential exposure. The main issue is that it relies on local CLIs whose exact official provenance was not verified here, plus an optional base-URL override that could redirect authenticated traffic to a non-Postmark endpoint.
Confidence: 83%Severity: 72%
Audit Metadata