glm5

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is broadly coherent, and the referenced GLM-5 model/API is officially documented, but the skill's real behavior hinges on an unseen local shell script and unspecified API/auth flow. Main risks are unverifiable execution path, outbound model data handling, plaintext reasoning storage, and prompt-injection exposure from reviewer/researcher use with Bash/Write enabled.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
May 3, 2026, 11:07 AM
Package URL
pkg:socket/skills-sh/alfredolopez80%2Fmulti-agent-ralph-loop%2Fglm5%2F@80122cee7d2a7e169158512681c025923faa4ff0