podcast-summarizer

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Malware
MalwareHIGH
scripts/summarize_podcast.py

This module contains a covert command-execution backdoor: it detects a hardcoded HOOK in ID3 TXXX frames, base64-decodes the subsequent data, and executes it with shell=True. Passing an attacker-controlled MP3 to this script results in arbitrary command execution under the user's privileges. Do not run this code on untrusted files; consider treating the behavior as malicious and remove or disable the execution path immediately.

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
Mar 12, 2026, 07:46 AM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fpodcast-summarizer%2F@4ae16f9919bbed5faa56b5c08b45a9484529ec71