Podcast Transcription Pipeline

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the advertised transcription capability is plausible, but the actual footprint centers on transitive skill installation through weakly verifiable CLIs and registry paths. The main concern is install-trust and inherited-permission risk, not confirmed malware or clearly malicious data exfiltration.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:38 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fpodcast-transcription-pipeline%2F@06c9e2c9a899ead7dffadf1fd8ada392f830e655