get-subtitles

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/cli.py

No clear malware, credential exfiltration, persistence, destructive behavior, reverse shell, or cryptomining is present in the supplied fragment. The primary security concern is unrestricted fetching of externally supplied URLs with redirects, which can cause SSRF, internal-service access, or resource exhaustion. The tool also handles API keys and performs legitimate but potentially consequential Bazarr/Radarr mutations. The fragment is syntactically incomplete and requires correction before execution. External URL fetching should enforce HTTPS, host or domain allowlists, redirect validation, private-network blocking, response-size limits, and content validation.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:01 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fget-subtitles%2F@bc35e670597f65ba31e26045b14570edbd27b3233f4f6ac0cce1ddce3403db58
Security Audit — socket — get-subtitles