gallery-dl
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomaly_scores.json
LOWAnomalyLOW
_scores.json
The fragment indicates a workflow that fetches a GitHub-hosted binary via curl without checksum verification and then likely uses/executes it, which is a meaningful supply-chain integrity risk. It also uses browser cookies for authenticated automated content retrieval, raising privacy/credential-handling concerns. No explicit malicious payload behavior is shown in the provided snippet, but the absence of actual code and the reliance on an unverified downloaded binary prevent a definitive benign assessment.
Confidence: 45%Severity: 64%
Audit Metadata