watch-video
Audited by Socket on Mar 11, 2026
1 alert found:
Obfuscated FileThe skill's purpose (engineer-grade video analysis from public URLs) is coherent with its described capabilities and workflow. The data flows and data sources are generally proportional to the task, leveraging public metadata, thumbnails, and optional transcription. However, there are notable security/privacy considerations due to outbound processing of video content to external services (transcription/analysis APIs) and potential full-download workflows. These data flows are acceptable for many legitimate workflows but warrant explicit user consent, transparent privacy handling, and clear disclosure of external data transmission. The overall risk is moderate (suspicious-to-benign depending on safeguards), with emphasis on ensuring credentials (API keys) are managed securely and that users understand when and what data is sent to third-party services.