z-api

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is not overtly malicious and uses an official npm-distributed CLI from the same vendor family, but its purpose and data flows are only partially coherent. The biggest issues are the naming/docs mismatch and the fact that all API access and authentication are routed through Membrane rather than directly to the stated service, increasing third-party trust and credential exposure. Overall this looks like a legitimate integration-platform skill with medium security risk, not confirmed malware.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fz-api%2F@8f8fc5ada5a7d9c1a436eaf5fa5da758860723c8