zai-cli

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is plausible and the documented service domains are official Z.AI properties, but the skill relies on runtime execution of an npm CLI whose official publisher relationship was not established in the provided evidence, while also forwarding an API key to that CLI. Broad Bash/file permissions and processing of untrusted web/repo content further raise risk. Main concerns are supply-chain trust, credential forwarding, and prompt-injection exposure rather than confirmed malware.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Mar 24, 2026, 03:48 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fzai-cli%2F@871bcea5739e211a89322db7d54a097a1a7dda31