zoom-mcp

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core skill is largely coherent and routes data to official Zoom-owned MCP and OAuth endpoints, but it documents an optional OAuth callback flow through webhook.site, a known interception service, which is disproportionate for handling sensitive auth codes. No malware or hidden execution is present, but the credential-handling guidance introduces meaningful security risk.

Confidence: 91%Severity: 57%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:18 AM
Package URL
pkg:socket/skills-sh/anthropics%2Fknowledge-work-plugins%2Fzoom-mcp%2F@7694580924cabc82bd83ce8a850805bc4ae2b603b47d810c44eb7f16f708c1b6
Security Audit — socket — zoom-mcp