zephyr-essential-cloud

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities are mostly aligned, and the CLI install source appears legitimate via official npm/docs. The main risk is that all authentication and Zephyr data access are mediated by Membrane rather than direct SmartBear APIs, creating a third-party credential and data trust dependency. No evidence of overt malware, hidden exfiltration endpoint, or deceptive installer was found.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 01:17 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzephyr-essential-cloud%2F@abff521b42dbc562f99d82b9f9319841486ffa05
Security Audit — socket — zephyr-essential-cloud