zoho-inventory

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities mostly align, and the npm CLI appears same-org and publicly sourced, but the integration routes Zoho access through ClawLink as a third-party intermediary that stores OAuth tokens and receives business data/action requests. This is a coherent SaaS integration pattern, not confirmed malware, yet it expands trust and write authority beyond Zoho's official direct API path.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fzoho-inventory%2F@7bc64dd86506310b93b9739e8423d64cd6e17b0176902e8bea2a7a78ec519b30
Security Audit — socket — zoho-inventory