zyte-api

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and uses a verifiable npm-hosted CLI from the apparent publisher ecosystem, but its true function is a Membrane-mediated Zyte integration rather than direct Zyte API access. The main risk is third-party credential/data routing through Membrane plus an unpinned CLI install, making this a medium-risk skill with coherent purpose but expanded trust boundaries.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fzyte-api%2F@e2038015558b824e0e09951bc6cd5a9245c2b96e
Security Audit — socket — zyte-api