skills/klh/speedy-claude/zod4/Gen Agent Trust Hub

zod4

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: HIGHMETADATA_POISONINGREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [METADATA_POISONING]: The skill presents itself as an expert guide for 'Zod 4', which is not a released or official version of the popular Zod validation library (the current stable version is v3). This deceptive framing is likely designed to mislead users or AI agents into adopting unverified tools.
  • [REMOTE_CODE_EXECUTION]: The skill explicitly instructs the user to run npx zod-v3-to-v4 in both SKILL.md and reference/migration-checklist.md. Running unverified code via npx from the public registry is a high-risk operation, especially when the tool mentioned does not exist in the official Zod ecosystem.
  • [COMMAND_EXECUTION]: The skill provides commands to install a non-existent version of the library: npm install zod@^4.5.0. Following these instructions would fail at best, or result in the installation of a malicious package if an attacker were to squat that version number on the registry.
  • [EXTERNAL_DOWNLOADS]: The instructions encourage the download of external packages and tools from the npm registry using deceptive version numbers and names that are not associated with the legitimate 'zod' project maintainers.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 6, 2026, 10:41 AM
Security Audit — agent-trust-hub — zod4