jellyfin-cli
Warn
Audited by Socket on Aug 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill's stated purpose and credential scope are coherent for a Jellyfin client, and the documented network flow targets the official Jellyfin API model. However, the skill asks the agent/user to run a bundled CLI executable that is not verifiable from the provided content, and that executable receives the Jellyfin API key; this makes the skill suspicious from a supply-chain and credential-forwarding standpoint even without evidence of confirmed malicious behavior.
Confidence: 86%Severity: 82%
Audit Metadata