youtube-summarize

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill coherently implements a YouTube transcript-based summarization workflow, but relies on an unverifiable external binary (openclaw-agent) obtained from non-official sources to perform transcript extraction. This creates a supply-chain risk and elevates the overall security risk above what would be expected for a self-contained tool. If the binary cannot be independently verified (signatures, hashes, or trusted distribution), treat as suspicious. Otherwise, the core capability (yt-dlp-based transcript extraction and text summarization) is acceptable for legitimate use when the binary dependency is replaced with a trusted, verifiable component.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 8, 2026, 03:52 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fyoutube-summarize%2F@7b91a6ce89b6dcb7aeb540263fe8b08a61660576