zephyr-essential-cloud
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose and capabilities are mostly aligned, and the CLI install source appears legitimate via official npm/docs. The main risk is that all authentication and Zephyr data access are mediated by Membrane rather than direct SmartBear APIs, creating a third-party credential and data trust dependency. No evidence of overt malware, hidden exfiltration endpoint, or deceptive installer was found.
Confidence: 87%Severity: 58%
Audit Metadata