glm-design-to-code-trial

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN overall with medium security risk. The skill's capabilities largely match its design-to-code purpose and use official Z.ai endpoints, but it has notable risk from raw `.env` key handling, writing model output to disk, and prompting installation of a separate plugin from a personal GitHub repo.

Confidence: 89%Severity: 52%
Audit Metadata
Analyzed At
May 3, 2026, 04:41 PM
Package URL
pkg:socket/skills-sh/kochetkov-ma%2Fclaude-brewcode%2Fglm-design-to-code-trial%2F@c8e96e18fac589386c79078d0192d84c5b43f6cf