zero-chat

Warn

Audited by Socket on Apr 22, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
zero-curl

This code is not overtly malware (it only calls curl), but it is a high-impact credential-handling wrapper: it unconditionally attaches a bearer token from an environment variable to requests whose destination and behavior are fully determined by caller-provided arguments. In a supply-chain context, this can become a token exfiltration or SSRF/enabled-auth-fetch primitive if the caller or inputs are attacker-influenced or compromised.

Confidence: 72%Severity: 67%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s API actions match its stated chat purpose and the destination is the expected VM0 API, but it relies on an undocumented `zero-curl` wrapper that automatically handles authentication. Because that CLI’s provenance and release path were not verified, this creates a high supply-chain and credential-forwarding risk disproportionate to a simple API guide.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:12 AM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fzero-use%2Fzero-chat%2F@4a381d49c83a6d997eb689b4c9689bdf46e22328