glm-design-to-code-trial
Warn
Audited by Socket on May 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
BENIGN overall with medium security risk. The skill's capabilities largely match its design-to-code purpose and use official Z.ai endpoints, but it has notable risk from raw `.env` key handling, writing model output to disk, and prompting installation of a separate plugin from a personal GitHub repo.
Confidence: 89%Severity: 52%
Audit Metadata