hifi-download

Fail

Audited by Socket on Apr 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: discovery features are coherent, but the download side expands scope into account-backed media acquisition and relies on a non-official TIDAL CLI to handle auth/tokens. Official-source API use for Spotify/Last.fm looks normal, while the TIDAL/Qobuz download workflow is less verifiable and disproportionate to a simple music recommendation skill.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:13 PM
Package URL
pkg:socket/skills-sh/psylch%2Fhifi-download-skill%2Fhifi-download%2F@87c6221b968b426b7f5ea004c26e5c16f6aed633