youtube-transcript-extract
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is benign and data flows appear limited, but the skill relies on an unpinned third-party `npx` execution with unclear provenance and uses wildcard activation broader than necessary. Main risk is supply-chain trust, not confirmed malware.
Confidence: 84%Severity: 72%
Audit Metadata