youtube-summarizer

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s core behavior matches YouTube summarization, but it relies on installing and executing an unrelated third-party GitHub project from a mutable branch, then uses that code to fetch data and optionally send files to Telegram. This is not confirmed malware, but the install trust and outbound messaging footprint make it higher risk than a normal documentation or API-only skill.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:06 AM
Package URL
pkg:socket/skills-sh/sales-skills%2Fsales%2Fyoutube-summarizer%2F@290fbe97716d20cc2f2913a5550c98e89b923ff7