qbt-hub

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core qBittorrent API management behavior is coherent and proportionate, but the skill forwards credentials to an arbitrary configurable host and includes a workflow that browses untrusted torrent sites before taking actions. There is no strong evidence of malware or hidden exfiltration, yet the custom host trust boundary and prompt-injection exposure make this higher risk than a simple local-only management skill.

Confidence: 89%Severity: 57%
Audit Metadata
Analyzed At
Apr 7, 2026, 02:17 AM
Package URL
pkg:socket/skills-sh/openminis%2Fminisskills%2Fqbt-hub%2F@214e11fd6958bb15b650eb98a5d831a02cd98abc
Security Audit — socket — qbt-hub