watch-cli-video-agent
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities largely match its stated video-analysis purpose, and the requested tools/API keys are mostly proportionate. However, the install path relies on an unpinned raw GitHub pipe-to-shell script with repo clone/pull behavior instead of a versioned, verifiable release, which creates medium supply-chain risk. Cookie use for login-walled content is purpose-related but expands sensitivity because session cookies may be exposed to external tooling and target platforms.
Confidence: 84%Severity: 62%
Audit Metadata