zoho-sign
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose mostly matches its capabilities, but it routes all Zoho Sign access and authentication through Membrane instead of directly to Zoho’s official APIs. That third-party proxy model and credential handling are disproportionate enough to raise medium risk, though the npm-based install path appears vendor-consistent rather than overtly malicious.
Confidence: 88%Severity: 58%
Audit Metadata