youtube-transcript-dossier

Warn

Audited by Socket on Sep 25, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/test_skill.py

The code is primarily a skill-directory validator and contains no direct evidence of malware, credential theft, exfiltration, persistence, or destructive behavior. The principal security concern is deliberate execution of an untrusted skill-local Python module through exec_module(), which can run arbitrary code with the validator's privileges. Path traversal is also possible in existence checks because referenced paths are not canonicalized or confined to skill_path. These are security design risks rather than demonstrated malicious behavior in this fragment.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 25, 2026, 10:52 AM
Package URL
pkg:socket/skills-sh/jpcaparas%2Fskills%2Fyoutube-transcript-dossier%2F@72d5fa2ee8e72744bafee72f57a908ab857c8760ca585f1e5fe1b17ff8d7bab7
Security Audit — socket — youtube-transcript-dossier