zoho-books

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability matches Zoho Books automation, and the CLI install path appears legitimate, but the skill is disproportionately dependent on a third-party intermediary that stores Zoho OAuth tokens and mediates all financial data flows and write actions. This makes the footprint riskier than a direct Zoho integration, especially given high-impact accounting and email operations.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fzoho-books%2F@ba15823b832710f97430f26dbe0d67dd9567badb647d5a0534c24baacf67638f
Security Audit — socket — zoho-books