youtube-to-bookplayer

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The approach is functionally sound for the intended objective but bears medium supply-chain and device-access risks. Strengthening would include: pinning/verifying tool hashes, adding robust error paths and rollback, optional content verification (checksum) of downloaded audio, explicit user consent for device transfer, and more resilient cleanup paths. Overall, the pattern is benign but requires governance around external tool integrity and device-transfer permissions.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 10:06 PM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fyoutube-to-bookplayer%2F@ed1291505b1512b28e77f56549c46cc4ac155cd9