manage
Audited by Socket on Jul 30, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the skill’s purpose matches its Kindle/Calibre capabilities, but its trust model is weak. The main concerns are transitive delegation to another skill and dependence on mixed-source DRM-removal binaries/ZIPs and tutorials, some outside official vendor channels. No strong evidence of credential theft or exfiltration appears in this router skill, but the supply-chain and host-mutation footprint are high for a consumer ebook workflow.
No direct evidence of malware or an explicit sabotage/backdoor mechanism is present in the provided fragment (it is an instruction/workflow text, not executable code). However, from a supply-chain security standpoint, it is still high-risk because it downloads and executes multiple third-party binaries (Kindle installer, DeDRM_tools, Kindle Key Finder) and modifies system firewall/ACL settings, while writing sensitive decrypted key material to local Calibre configuration. The workflow claims hash verification against references/versions.md and includes guards for placeholder values, which reduces some risk, but dynamic tag selection (when gh is available) and the general “download-then-execute” pattern remain notable concerns. Additional context (the referenced scripts/binaries/plugin code) would be required for a definitive malware verdict.