prowlarr

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill’s footprint is coherent with its stated purpose: it provides read/write management for Prowlarr indexers via a locally hosted API, uses a local script wrapper for API calls, and handles sensitive operations with explicit confirmation for deletions. The credential handling relies on a local env file, which is reasonable for a development/lab setup but requires strict file permissions and secure storage to avoid leakage. There are no obvious unverifiable binaries or external downloads, and network interactions are limited to the local Prowlarr instance and connected apps. Overall, the skill is BENIGN with elevated caution due to credential and local secret handling; treat secret files as sensitive and ensure proper access controls.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 05:33 PM
Package URL
pkg:socket/skills-sh/jmagar%2Fclaude-homelab%2Fprowlarr%2F@25f96dda55f66a91d89fd3b57702eea2aa2e02b6