zoho

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The Zoho API usage itself is coherent and mostly points to official Zoho endpoints, but the skill’s trust model is weak: it relies on an unverifiable repo-local CLI wrapper from a personal GitHub account, uses transitive skill installation, and asks that wrapper to handle long-lived Zoho credentials. The optional meeting summarizer also expands data flow to a third-party AI service. This is not confirmed malware, but the install provenance and credential-forwarding footprint are disproportionate enough to warrant caution.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
Apr 17, 2026, 11:14 PM
Package URL
pkg:socket/skills-sh/shreefentsar%2Fclawdbot-zoho%2Fzoho%2F@6d5cece74b5a899e518a90d7a71fcf61d38f3666