zoho-inventory
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's CRUD scope matches its Zoho Inventory purpose, and there is no malware-style payload or installer. However, it requires sending a reusable Maton API key and all Zoho business data through Maton-operated proxy/control domains instead of Zoho's official API, with some endpoint-documentation inconsistency. This is a moderate security risk from third-party credential/data mediation rather than confirmed malicious behavior.
Confidence: 87%Severity: 56%
Audit Metadata