jellyfin-cli

Warn

Audited by Socket on Aug 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose and credential scope are coherent for a Jellyfin client, and the documented network flow targets the official Jellyfin API model. However, the skill asks the agent/user to run a bundled CLI executable that is not verifiable from the provided content, and that executable receives the Jellyfin API key; this makes the skill suspicious from a supply-chain and credential-forwarding standpoint even without evidence of confirmed malicious behavior.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Aug 5, 2026, 09:21 PM
Package URL
pkg:socket/skills-sh/magnus919%2Fagent-skills%2Fjellyfin-cli%2F@79e368a6b236d9d5a7c616a8e0610bd6923c616c255afd291d4fe34cdaccb66b
Security Audit — socket — jellyfin-cli