Get a demo — 30 minutes →
Skill scan report

VLM

View on GitHub
10 Low Automated analysis flagged 1 potential risk pattern.

What this skill does

Implement vision-based AI chat capabilities using the z-ai-web-dev-sdk for image analysis and multimodal interactions.

github/jjyaoao - Third-party dependency usage - 2.7k stars

ThreatsThird-party dependency usage

Threat analysis

Third-party dependency usage1 finding

Skill info

Namejjyaoao/vlm
Registrygithub
Version5432566
PURLpkg:github/jjyaoao/HelloAgents@5432566?skill=vlm
Stars2.7k

Assessments (1)

Third-party dependency usage1 finding MEDIUM
MEDIUM

Third-party dependency usage via local-llm-review

scripts/vlm.ts

The code imports and uses 'z-ai-web-dev-sdk' to interact with a model ('glm-4.6v') and sends image URLs to an external service. This could pose a risk if the SDK is not properly secured or if the mode

Badge

Add the Anomity scan badge for VLM to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/jjyaoao/vlm/)
HTML
<a href="https://anomity.ai/skills/github/jjyaoao/vlm/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of VLM? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok