gallery-dl

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
_scores.json

The fragment indicates a workflow that fetches a GitHub-hosted binary via curl without checksum verification and then likely uses/executes it, which is a meaningful supply-chain integrity risk. It also uses browser cookies for authenticated automated content retrieval, raising privacy/credential-handling concerns. No explicit malicious payload behavior is shown in the provided snippet, but the absence of actual code and the reliance on an unverified downloaded binary prevent a definitive benign assessment.

Confidence: 45%Severity: 64%
Audit Metadata
Analyzed At
May 20, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/terminalskills%2Fskills%2Fgallery-dl%2F@b6606961c0a9cb1fccbdeba0824eacc975f652a2
Security Audit — socket — gallery-dl