Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/search.mjs:50
Security audit
Security checks across malware telemetry and agentic risk
This appears to be a straightforward Z.AI web search skill, but searches, URLs, and the ZAI_API_KEY are used with external network services.
This skill is reasonable to install if you want Z.AI-backed web search. Before using it, set a dedicated ZAI_API_KEY, avoid sensitive search queries, treat returned web text as untrusted information, and only extract pages or URLs you intentionally want the agent to read.
64/64 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access