jellyfin-security-plugin

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent for a Jellyfin security plugin and does not show clear malicious or covert behavior, but its install path depends on a third-party personal GitHub repository and unsigned release ZIP for server-side auth code that will handle sensitive credentials. That supply-chain trust gap makes the skill higher risk than an official Jellyfin-source plugin.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:54 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fsecurity-skills%2Fjellyfin-security-plugin%2F@77ea9ed1b8824e8a8f1d488ab53cc2712aad33a5f5d4ab9205facb3959678ca5
Security Audit — socket — jellyfin-security-plugin