web-reader

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly fit its stated web-reading purpose, and the visible network flow appears to target Z.AI web-reader functionality rather than an obvious exfiltration endpoint. The main concern is install/execution trust: the exact `z-ai-web-dev-sdk` package provenance is not clearly verified from official documentation, while the skill routes arbitrary external web content through a backend SDK/CLI and encourages downstream processing of untrusted content, creating medium supply-chain and prompt-injection risk.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 20, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/Hainrixz%2Fclaude-webkit%2Fweb-reader%2F@c7261e40aebaf9bbb55189169b712077ef53a1e9