zlib-download
Audited by Socket on Sep 15, 2026
3 alerts found:
SecurityAnomalyx2SUSPICIOUS. The skill's basic book-search purpose is coherent, but its trust model is not: it installs a third-party GitHub-release binary and forwards an API key to it, creating a high supply-chain and credential-forwarding risk. The markdown command examples are not load-time execution, and the search-result prompt-injection surface is routine, but the external binary dependency makes the overall skill high risk.
The code appears to be a legitimate book-search/download CLI, with no clear evidence of intentional malware or covert exfiltration. Primary risks are plaintext credential/token storage, execution of an unverified executable selected from PATH or configuration, configurable redirection to an untrusted mirror, and insufficient sanitization of Anna's Archive filenames. The code should be reviewed together with the local Zlibrary module and annas-mcp binary before treating those dependencies as trusted.
The fragment appears to be a legitimate dependency installer rather than malware. Its primary security concern is supply-chain integrity: it installs requests and a remote executable without explicit version/hash/signature verification, and it extracts an untrusted archive without safety validation. Use of the fixed GitHub URL and version limits direct input manipulation, but a compromised repository, release, or transport-adjacent artifact could result in arbitrary code execution when annas-mcp is later run. Review release provenance and add artifact checksums or signatures before use.