video-download

Warn

Audited by Socket on Apr 11, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/download-fallback.sh

This appears to be a functional third-party automation/downloader rather than an explicit malware implant, with no obvious credentials or persistence. However, it introduces meaningful security risk: it executes JavaScript in a remote page context (agent-browser eval) and then downloads content from a URL extracted from untrusted remote state without strong allowlisting/validation. If greenvideo.cc or the page state is compromised or returns unexpected values, the host running the script could download unintended content from arbitrary network locations and write it to the filesystem (operator-controlled directory).

Confidence: 64%Severity: 62%
AnomalyLOW
SKILL.md

SUSPICIOUS. The primary yt-dlp path is coherent and mostly benign, but the Douyin/TikTok fallback is a material inconsistency: it sends URLs and browser-driven session context through an unrelated third-party site (`greenvideo.cc`) instead of official endpoints. Cookie-based retry is somewhat proportionate for restricted downloads, yet combining browser cookie access, untrusted browser automation, and third-party parsing raises medium-high security risk.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Apr 11, 2026, 01:35 AM
Package URL
pkg:socket/skills-sh/ArcoCodes%2Frenoise-plugins-official%2Fvideo-download%2F@c258f5634361ef7bcc39e025da620d28de827dc8