zoho-books

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent as a Membrane-based Zoho Books integration, and the install path is a normal npm package rather than an unverifiable binary. However, it routes credentials and accounting data through Membrane-managed infrastructure instead of direct Zoho APIs, uses an unpinned global CLI install, and supports dynamic action creation on the third-party platform. This is not confirmed malicious, but it introduces meaningful trust and data-flow risk beyond a simple direct API integration.

Confidence: 84%Severity: 53%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzoho-books%2F@a48d4f4b8fcd1aa68913df5a782e2d4f6021f6bf
Security Audit — socket — zoho-books