zencom

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with its stated purpose and uses an official npm-distributed CLI, so it does not look overtly malicious. However, it routes authentication and ZEN.COM operations through Membrane as an intermediary, uses floating installs, and enables an agent to perform potentially sensitive financial-platform actions via a third-party CLI/service. That makes it coherent but medium risk rather than benign.

Confidence: 83%Severity: 57%
Audit Metadata
Analyzed At
May 1, 2026, 03:50 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzencom%2F@af7d235eac15ff9e0f2af3548bf9a49add80f822
Security Audit — socket — zencom