aa-book

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No direct evidence of embedded malicious code exists in the provided documentation fragment. The dominant concerns are operational and supply-chain: unspecified network endpoints for ingestion/logging and reliance on external binaries (aa-book, pdf-brain, Calibre) whose provenance is not validated create moderate risk of data exfiltration or misuse. Recommend verifying binaries' sources and signatures, explicitly configuring and validating ingestion/log endpoints with strong auth and TLS, sandboxing downloads and conversions, and auditing background-job behavior and logs before trusting the pipeline with sensitive or copyrighted material.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 25, 2026, 03:44 AM
Package URL
pkg:socket/skills-sh/joelhooks%2Faa-download%2Faa-book%2F@139906b5d443ad7b37a1c4cbf0a2c5062247a494