zendesk-guide

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's basic Zendesk purpose is coherent, and the CLI install path looks like an official npm distribution, but the core data flow is mediated by Membrane rather than Zendesk's official API. That third-party proxy model materially expands trust and exposes Zendesk traffic and auth handling to an intermediary, making this medium risk despite low evidence of outright malware.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 2, 2026, 01:24 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzendesk-guide%2F@66946fd8ccc692e3d856d35414474a2842b7a73f