zephyr-squad-legacy

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities are mostly aligned, and the CLI install source is official and same-org, so this is not malware-like. The main risk is architectural: all Zephyr access and auth are funneled through Membrane as a third-party intermediary rather than direct SmartBear APIs, and the skill encourages dynamic remote action creation. That makes the footprint broader and less direct than a simple Zephyr integration, yielding moderate security risk but not confirmed malicious behavior.

Confidence: 88%Severity: 53%
Audit Metadata
Analyzed At
May 1, 2026, 01:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzephyr-squad-legacy%2F@966e38f6aa42ac433f99edd549eef6d8e733e0f1
Security Audit — socket — zephyr-squad-legacy