video-analyzer
Audited by Socket on Jul 30, 2026
2 alerts found:
AnomalySecurityNo clear evidence of intentional malware/backdoor in the provided fragment, but there are significant security/supply-chain concerns: (1) yt-dlp downloads with TLS certificate verification disabled (--no-check-certificates), enabling MITM; (2) yt-dlp/ffmpeg executables are chosen via environment variables (YTDLP_PATH/FFMPEG_PATH), which could enable execution of attacker-controlled binaries if the environment is compromised; (3) the code sends base64-encoded user content (audio and frames) to OpenAI/Gemini endpoints; and (4) API keys are read from .env and Gemini keys are placed in URL query parameters. Final confidence is limited because the snippet appears truncated and the full main/analyze_video/template generation logic is not shown.
SUSPICIOUS: the overall workflow matches the stated video-analysis purpose and credential use is proportionate, but the skill depends on undocumented local binaries (`.bin/yt-dlp`, `.bin/ffmpeg`) whose provenance is not verifiable from the skill text. No clear malicious exfiltration or deceptive routing is shown, yet the opaque executable trust chain and transitive skill usage make it a high security-risk skill rather than a benign one.