zoho-expense

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities fit its stated Zoho Expense integration purpose, and the CLI comes from an official npm package tied to the same publisher. However, all authentication and API interaction are mediated through Membrane rather than direct Zoho endpoints, so credentials and business data are entrusted to a third-party platform. Combined with mutable `@latest` installs, this makes the skill higher-risk than a direct API integration, though not malicious.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 05:49 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzoho-expense%2F@d7e81035872a69364307d01ab462b388618a9aac
Security Audit — socket — zoho-expense