zoho-bigin

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated Zoho Bigin integration purpose, and its install path is a legitimate npm-distributed vendor CLI rather than a stealth payload. However, the core data flow routes authentication and API traffic through Membrane infrastructure instead of directly to Zoho, creating a significant third-party credential and CRM data exposure surface that is disproportionate for users expecting a direct service integration.

Confidence: 89%Severity: 66%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:45 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzoho-bigin%2F@4a5a75a1598deddca9062d29359de6fb79db3a95