zephyr-scale

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated Zephyr Scale purpose, and the CLI install appears to be an official same-vendor npm package rather than an obvious malicious payload. The main concern is data-flow integrity: all authentication and API traffic are brokered through Membrane instead of direct SmartBear endpoints, giving a third-party platform access to Zephyr data and potentially tokens. This is not confirmed malware, but it is a meaningful trust and privacy risk that elevates the skill above benign.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Mar 13, 2026, 12:53 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzephyr-scale%2F@960640a02cee5d5ba23cd691a5536cdb4cd2565f