video-to-subtitle-summary

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s main behavior matches its stated purpose, and its core dependencies/endpoints are largely legitimate. However, it is not fully benign: it reads raw credentials from shell config files and routes user data through a third-party aggregator (TikHub) plus ByteDance’s speech API. Overall this is coherent but moderately risky due to credential handling and external data flows, so the skill is best classified as suspicious rather than malicious.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
May 7, 2026, 08:41 PM
Package URL
pkg:socket/skills-sh/imlewc%2Fvideo-to-subtitle-summary-skill%2Fvideo-to-subtitle-summary%2F@d66d3a67d57a38e6503e54a63cf1764c61018950