zoho-mail

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core function is coherent, and the CLI source appears official, but it routes Zoho auth and mailbox data through Membrane rather than directly to Zoho. That third-party credential/data mediation plus email-sending capability makes the skill medium risk even without signs of overt malware.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:14 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzoho-mail%2F@96f7fee512b5a54031bd39f91150923ef0aeeb53
Security Audit — socket — zoho-mail