glmv-web-replication

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior is mostly consistent with its stated purpose, and its dependencies appear to be official tools rather than unknown binaries. However, it grants broad automation for recursively exploring and reproducing external websites, relies on user-asserted authorization only, and combines untrusted web content ingestion with write-capable agent behavior, making indirect prompt-injection and misuse risks material. Not malicious on its face, but medium risk as an AI agent skill.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
May 11, 2026, 04:13 AM
Package URL
pkg:socket/skills-sh/zai-org%2FGLM-V%2Fglmv-web-replication%2F@8e32fff9f764b5a4f8c1d14c9756ab07a98bec9b
Security Audit — socket — glmv-web-replication