hifi-download

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core capabilities mostly match its stated music discovery/download purpose, and the flagged command patterns are documentation artifacts, not executable injection. The main risk is trust and credential handling around the unofficial tiddl CLI plus missing code for setup/run scripts, which prevents verification of exact dependency and network behavior. Not confirmed malware, but elevated security risk due to third-party credential/token handling and unverifiable implementation details.

Confidence: 87%Severity: 74%
AnomalyLOW
run.sh

The code is a straightforward virtual-environment script runner with no direct evidence of malware. Its primary security weakness is unchecked path traversal in the script-name argument, allowing execution of unintended Python files accessible through relative paths. Restrict the name to an allowlisted filename or validate it as a basename without path separators and traversal components.

Confidence: 98%Severity: 52%
Audit Metadata
Analyzed At
Sep 14, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/psylch%2Fmedia-master%2Fhifi-download%2F@7acea4808449be9a348012a0de7f7cf6ce102fbf5ea21be658240b70ee81b4ca
Security Audit — socket — hifi-download