zoho

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the install path appears same-org and not overtly malicious, but the skill's core model is a third-party gateway that stores its own credential locally and mediates all Zoho access through ClawLink instead of direct Zoho APIs. That data-flow design is broader and riskier than a typical service-specific integration, so the skill is internally coherent but trust-heavy and medium/high risk.

Confidence: 83%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fzoho%2F@f6f76ab8a8ac2d400eb962d001d43faa933ba98874b536566047ae98b1e16ea4
Security Audit — socket — zoho