youtube-search

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill coherently implements a YouTube search utility using yt-dlp and formats structured results for downstream use. The main concerns are: (1) potential command-injection risk if user-provided input is not sanitized before embedding in shell commands, and (2) unverifiable binary installation of yt-dlp via an external tool manager without verifiable provenance. Otherwise, the data flow is self-contained (no credentials, no unexpected exfiltration) and the capabilities align with the stated purpose. Treat the skill as SUSPICIOUS pending improvements to input sanitization and verifiable dependency provenance.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/mathews-tom%2Fpraxis-skills%2Fyoutube-search%2F@02cabbaef7bae84e6687e9b37ba7b93de591e7fa