postmark-automation
Warn
Audited by Socket on Apr 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned and uses an official same-org Rube/Composio integration, but it routes Postmark access through a third-party MCP intermediary and enables high-impact actions like sending emails and editing server settings. Main risk is intermediary trust and autonomous external actions, not confirmed malware.
Confidence: 88%Severity: 74%
Audit Metadata