glm

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is plausible, but the skill's trust chain is weak because it relies on an unverified local `zai` CLI that does not clearly map to official Z.ai distribution. Data flow to GLM is expected, yet the unclear CLI ownership, command-surface mismatch, and self-modifying instructions make the skill higher risk than a normal documentation wrapper.

Confidence: 84%Severity: 83%
Audit Metadata
Analyzed At
Jul 24, 2026, 11:28 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fglm%2F@d167f575c30c22ea890b1983f2a7e1f3aa971ea88a77d3286bf8c9b51bd9d3e8
Security Audit — socket — glm