zephyr-squad-legacy
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and capabilities are mostly aligned, and the CLI install source is official and same-org, so this is not malware-like. The main risk is architectural: all Zephyr access and auth are funneled through Membrane as a third-party intermediary rather than direct SmartBear APIs, and the skill encourages dynamic remote action creation. That makes the footprint broader and less direct than a simple Zephyr integration, yielding moderate security risk but not confirmed malicious behavior.
Confidence: 88%Severity: 53%
Audit Metadata