NYC

yt-dlp-downloader

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Functionally legitimate for downloading and extracting media via yt-dlp/ffmpeg. Primary security concerns are operational: (1) Overbroad permission request ('all') should be narrowed to network and limited filesystem access; (2) Default recommendation to always use --cookies-from-browser chrome unnecessarily exposes sensitive browser cookies—cookies access must be requested only when needed and with explicit consent; (3) Constructing shell command strings from user input without shown sanitization risks command injection—use argument lists or safe APIs and validate/escape all user-supplied inputs. No direct evidence of obfuscated or malicious payloads, no hardcoded secrets, and no external exfiltration endpoints present in the provided material. Recommend reducing default cookie usage, removing broad 'all' permission, and demonstrating secure command execution patterns.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:10 PM
Package URL
pkg:socket/skills-sh/mapleshaw%2Fyt-dlp-downloader-skill%2Fyt-dlp-downloader%2F@8da2e2ec3c38c6bb79d6a1718984be7b80aef38f