zype

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is Zype integration, but its actual operation depends on a third-party Membrane CLI and proxy that handles authentication and relays API traffic. The install source is relatively trustworthy (official npm package), so this is not strong malware evidence, but the data flow is not direct to Zype and credentials/trust are delegated to an intermediary service, making the footprint broader than a typical single-service integration skill.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Apr 28, 2026, 05:27 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzype%2F@a6bb6e75f956210606bb9d202af4910be71a84df