zencom
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly aligned with its stated purpose and uses an official npm-distributed CLI, so it does not look overtly malicious. However, it routes authentication and ZEN.COM operations through Membrane as an intermediary, uses floating installs, and enables an agent to perform potentially sensitive financial-platform actions via a third-party CLI/service. That makes it coherent but medium risk rather than benign.
Confidence: 83%Severity: 57%
Audit Metadata