youtube-thumbnail

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated goal of autonomous YouTube thumbnail generation with multi-backend support is broadly coherent, but the actual footprint raises security concerns. The use of an unverifiable external binary (mcp-imagen-go) and broad credential exposure paths (multiple API keys) combined with autonomous execution create non-trivial risk. While not proven malicious, the configuration warrants cautious evaluation, restricted trust, and explicit user consent for autonomous actions. Treat as SUSPICIOUS (with high caution) due to supply-chain and data-flow concerns.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/biggora%2Fclaude-plugins-registry%2Fyoutube-thumbnail%2F@858d2e089c835f1dc89fbae68b9b67bd15e3de91