zitadel

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the install source is an official npm package rather than an unknown binary. However, it routes ZITADEL access through Membrane’s third-party CLI/platform instead of direct official ZITADEL APIs, creating moderate credential and data-flow trust risk; use is coherent but not low-risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:56 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzitadel%2F@5f85e64794be08ab1a6bf6ef4816d3f86cc81148