jellyfin-security-plugin
Warn
Audited by Socket on Jun 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is coherent for a Jellyfin security plugin and does not show clear malicious or covert behavior, but its install path depends on a third-party personal GitHub repository and unsigned release ZIP for server-side auth code that will handle sensitive credentials. That supply-chain trust gap makes the skill higher risk than an official Jellyfin-source plugin.
Confidence: 100%Severity: 60%
Audit Metadata