zoho-bigin

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose matches CRM integration, but its actual footprint routes credentials and Zoho Bigin actions through ClawLink's third-party CLI and hosted service instead of official Zoho APIs. This is not clearly malicious from the provided content, yet the mediated data flow, local credential storage, and ability to perform writes make it a medium-risk integration that should only be trusted if ClawLink package ownership and official docs are independently verified.

Confidence: 77%Severity: 64%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fzoho-bigin%2F@fa945f2289f060dd5069e25d828c28043c7a5e168c311a3ca6c287d5c656ebb1
Security Audit — socket — zoho-bigin