zoho-inventory

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's business purpose is plausible, but its actual footprint centers on a third-party Membrane platform that handles authentication, action generation, and all API traffic instead of direct Zoho API use. The npm install path is relatively standard, so this is not confirmed malware, but the intermediary credential/data flow and mutable external CLI make the skill medium-high risk.

Confidence: 88%Severity: 71%
Audit Metadata
Analyzed At
May 1, 2026, 04:46 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzoho-inventory%2F@c8c23334e39fb2b778e97d846489905ada12c73e
Security Audit — socket — zoho-inventory