qzcli
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s job-management behavior matches its stated purpose, but the trust chain is weak. It asks users to install and run credential-handling code from a personal GitHub repository with unpinned dependencies and then pass Qizhi credentials to it, which is a meaningful supply-chain risk even without clear evidence of malicious intent.
Confidence: 84%Severity: 72%
Audit Metadata