glm
Warn
Audited by Socket on Jul 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is plausible, but the skill's trust chain is weak because it relies on an unverified local `zai` CLI that does not clearly map to official Z.ai distribution. Data flow to GLM is expected, yet the unclear CLI ownership, command-surface mismatch, and self-modifying instructions make the skill higher risk than a normal documentation wrapper.
Confidence: 84%Severity: 83%
Audit Metadata