bilibili-transcript

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and requested access are mostly coherent for transcript extraction, and the PyPI Whisper install is standard. However, the unseen local script prevents verification of actual credential/data handling, and the stated model fetch from third-party hf-mirror weakens install/data-flow trust. This looks more like a plausible but medium-risk workflow skill than malware.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Sep 19, 2026, 08:44 AM
Package URL
pkg:socket/skills-sh/itgoyo%2Fbilibili-transcript-skill%2Fbilibili-transcript%2F@2aab8773f92ba47242dfa69c5f3e5ac5ab91efe0
Security Audit — socket — bilibili-transcript