ytmusic-hub

Warn

Audited by Socket on Mar 28, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
scripts/ytmusic_client.py

No clear evidence of classic malware (e.g., reverse shells, persistence, or direct credential exfiltration) is visible in this fragment. The dominant finding is high-risk behavior: the module globally disables TLS certificate and hostname verification in urllib3 and globally overrides socket.getaddrinfo to redirect selected domains to runtime-determined IPs derived from DoH. This substantially weakens transport-layer security and can enable MITM/traffic redirection, making the dependency dangerous unless carefully sandboxed and justified in a trusted environment.

Confidence: 74%Severity: 83%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core purpose matches YouTube Music management, and the main library comes from an official registry, but the skill handles raw browser cookies, stores reusable auth headers locally, and explicitly disables SSL verification while patching DNS/network resolution. Those controls are disproportionate and create substantial credential and account-action risk even without clear evidence of third-party exfiltration.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Mar 28, 2026, 11:50 AM
Package URL
pkg:socket/skills-sh/OpenMinis%2FMinisSkills%2Fytmusic-hub%2F@4a989482c3994d14dc29807842bec74268fd8d85