zoho-catalyst

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s functionality broadly matches its stated Zoho Catalyst purpose, and the CLI comes from an official npm package with matching vendor docs. The main concern is architectural: all authentication and API traffic are mediated by Membrane, a third-party intermediary, rather than going directly to Zoho’s native APIs. That makes this a moderate trust and data-flow risk, not confirmed malware.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
Apr 2, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzoho-catalyst%2F@6e888e82bc0f159f1bc7ccd891bb771c2b01c218