zendesk-guide

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent as a Zendesk Guide integration, and its CLI comes from an official npm package rather than an unverifiable binary. However, all authentication and API traffic are routed through Membrane instead of directly to Zendesk, so credentials and data are entrusted to a third-party gateway. That makes the footprint larger than a direct Zendesk skill and raises medium security risk, but not enough evidence suggests confirmed malware.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 04:07 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzendesk-guide%2F@12add8f6e87f6429b77e579c378e3c14000556c7
Security Audit — socket — zendesk-guide