ingest-audiobook
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s media-ingest purpose mostly matches its capabilities, but trust is weakened by unpinned runtime installs and, more importantly, by routing Audible authentication and activation-byte handling through an unofficial third-party CLI. No clear malicious exfiltration endpoint is shown, but credential forwarding plus mutable package execution make the overall risk medium-high.
Confidence: 86%Severity: 81%
Audit Metadata