zephyr-scale

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s functionality broadly matches its Zephyr Scale purpose, and the CLI install path is from an official registry, so this is not clearly malicious. However, it routes authentication, data access, and action generation through Membrane rather than directly to SmartBear, creating a meaningful third-party trust and credential-forwarding risk with mutable CLI installation and server-side action building.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzephyr-scale%2F@d6b77a800c44d7b41a5809618d6cea16c4df1a61
Security Audit — socket — zephyr-scale