youtube-digest

Warn

Audited by Socket on Jul 30, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
extraction/package-lock.json

No concrete malware behavior can be confirmed from the provided lockfile/metadata fragment alone. The primary supply-chain security concern is the package’s reliance on local file: dependencies from ../../../vendor/*, which bypasses registry integrity/provenance controls and could execute attacker-modified code during install/build/runtime. To finalize malware/safety determination, the source code and npm lifecycle scripts of the local vendored dependencies (and any scripts in the published package) must be reviewed.

Confidence: 46%Severity: 58%
AnomalyLOW
extraction/register-hook.mjs

This file is a thin bootstrap that registers a local Node.js resolve/loader hook. The snippet itself contains no direct malicious logic, but loader/resolve hooks are powerful and can be used for dependency substitution or runtime tampering. The overall security assessment hinges entirely on the contents/behavior of resolve-hook.mjs, which is not provided here. Review resolve-hook.mjs for any import redirection, dynamic module replacement, network communication, or data handling.

Confidence: 55%Severity: 50%
Audit Metadata
Analyzed At
Jul 30, 2026, 08:00 PM
Package URL
pkg:socket/skills-sh/melodic-software%2Fclaude-code-plugins%2Fyoutube-digest%2F@8a0cbffc07585fb7d4f3a80a7a5e8db297b6f00a5d27eb920ccacdd774ad2916
Security Audit — socket — youtube-digest