watch-cli-video-agent

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities largely match its stated video-analysis purpose, and the requested tools/API keys are mostly proportionate. However, the install path relies on an unpinned raw GitHub pipe-to-shell script with repo clone/pull behavior instead of a versioned, verifiable release, which creates medium supply-chain risk. Cookie use for login-walled content is purpose-related but expands sensitivity because session cookies may be exposed to external tooling and target platforms.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 17, 2026, 08:01 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdevtools-skills%2Fwatch-cli-video-agent%2F@af92eef47d7efff79b331876db1a253ce2378c9c