zentao

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities fit its ZenTao-management purpose, but it relies on an unofficial third-party CLI and asks users to provide raw ZenTao credentials to it. The npm distribution path is normal and publicly linked to source, so this is not confirmed malware, but the combination of credential forwarding and transitive skill installation creates medium risk and warrants caution.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 10, 2026, 03:12 AM
Package URL
pkg:socket/skills-sh/leeguooooo%2Fzentao-mcp%2Fzentao%2F@1245a8d13375e2825a1a841873b861714a35966b