jellyfin-security-plugin

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill guides users to install a plugin by adding a repository URL (https://raw.githubusercontent.com/ZL154/JellyfinSecurity/main/manifest.json) that belongs to an unverified third-party account. Installing the plugin results in the execution of external binary code on the server.- [COMMAND_EXECUTION]: Manual installation and development instructions involve executing multiple shell commands, including cloning source code with git, building the project using 'dotnet build', and copying binary DLL files into the server's plugin directory.- [EXTERNAL_DOWNLOADS]: The plugin is documented to perform automated downloads of geographic databases from MaxMind, which is a well-known service for IP intelligence data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 01:53 AM
Security Audit — agent-trust-hub — jellyfin-security-plugin