zlib-download

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The CLI tool provides a coherent, purpose-aligned workflow for searching and downloading from Z-Library and Anna's Archive, with practical workflow steps and fallbacks. However, it introduces notable security and governance risks due to plaintext credential storage, token caching, and external binaries (annas-mcp) fetched via setup.sh. The overall security posture is Medium-high risk primarily driven by credential management and external dependencies. Mitigations should include encrypted or scoped secret storage, explicit per-action consent prompts, hardened logging to avoid credential leakage, pinning of external binaries/versions, and improved handling of API keys (especially the Anna's Archive donation-based model). Suggested enhancements: implement secret vault integration or OS-level keyring; enforce strict file permissions; add TLS/endpoint pinning and versioned dependency checks; introduce per-download user confirmation and hash verification for downloaded books.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 08:05 PM
Package URL
pkg:socket/skills-sh/psylch%2Fmedia-master%2Fzlib-download%2F@51e59222994a479c5d1215d741ef73cdfb66036c