zenstudio
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly match its stated ZenStudio purpose, and the service endpoint looks official, but trust is weakened because it installs an external npm CLI with unclear same-org provenance and then forwards the API key to that CLI for all authenticated actions. This is not confirmed malware, but it is a meaningful supply-chain and credential-forwarding risk.
Confidence: 84%Severity: 64%
Audit Metadata