postmark-automation

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and uses an official same-org Rube/Composio integration, but it routes Postmark access through a third-party MCP intermediary and enables high-impact actions like sending emails and editing server settings. Main risk is intermediary trust and autonomous external actions, not confirmed malware.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 27, 2026, 10:56 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fpostmark-automation%2F@1a9f57e9171ef140b6e9bbc0fbca0588c0541b7f