zooz

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent and not overtly malicious, but it routes ZOOZ access, credentials, and action execution through Membrane rather than directly to ZOOZ. That third-party broker model is disclosed and proportionate to the skill’s purpose, so this is not malware; however, the indirect data flow, server-side credential handling, mutable @latest CLI install, and potential payment-impacting actions make it medium risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 10:39 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzooz%2F@a032a748f00fdb95ff4996667c55820c7311c750
Security Audit — socket — zooz