glmv-web-replication

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s capabilities mostly match its stated purpose: public-site browsing, screenshot capture, asset download, and local blueprint generation for frontend replication. The main concerns are medium-risk transitive dependency trust and the high-volume processing of untrusted web content while having file-write capability, which could expose the agent to indirect prompt injection. Overall this is better classified as SUSPICIOUS than benign due to those execution and content-ingestion risks, but there is no strong evidence of credential harvesting, covert exfiltration, or confirmed malicious intent.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 2, 2026, 03:15 AM
Package URL
pkg:socket/skills-sh/zai-org%2FGLM-skills%2Fglmv-web-replication%2F@05a575c8fe360e6bd646da545c80dbbf17c7a556