web-reader
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities mostly fit its stated web-reading purpose, and the visible network flow appears to target Z.AI web-reader functionality rather than an obvious exfiltration endpoint. The main concern is install/execution trust: the exact `z-ai-web-dev-sdk` package provenance is not clearly verified from official documentation, while the skill routes arbitrary external web content through a backend SDK/CLI and encourages downstream processing of untrusted content, creating medium supply-chain and prompt-injection risk.
Confidence: 82%Severity: 58%
Audit Metadata