zendesk-sunshine

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated purpose, and the CLI comes from an official npm package with documented commands. The main concern is data-flow integrity: Zendesk Sunshine access is routed through Membrane's intermediary platform and CLI, so authentication and API activity are delegated to a third party rather than going directly to Zendesk. This is coherent with the skill's design but expands trust and centralizes credentials/actions outside the official service path. Overall this is not confirmed malicious, but it carries medium risk due to third-party mediation and unpinned CLI installs.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 20, 2026, 06:59 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzendesk-sunshine%2F@3e3c14045f8d5234ac90b94a7b85ebc5fa028dc1
Security Audit — socket — zendesk-sunshine