ingest-audiobook

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s media-ingest purpose mostly matches its capabilities, but trust is weakened by unpinned runtime installs and, more importantly, by routing Audible authentication and activation-byte handling through an unofficial third-party CLI. No clear malicious exfiltration endpoint is shown, but credential forwarding plus mutable package execution make the overall risk medium-high.

Confidence: 86%Severity: 81%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fingest-audiobook%2F@a01a15d81154085d612571f511fdbac3c1ac7b7a
Security Audit — socket — ingest-audiobook