qb-downloader

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aims to automate legitimate workflow steps for adding torrents to a qBittorrent instance. Its data flows (site -> magnet link extraction -> qBittorrent add -> verify) are coherent with the stated purpose. However, there are notable security considerations: magnet links may contain passkeys which should not be logged; the qBittorrent API endpoint is exposed and used without explicit authentication handling shown; and there is potential for data leakage via logs or intermediaries. Overall, the footprint is proportionate to the stated purpose but warrants attention to credential handling, access control, and logging to reduce data leakage risk.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 09:59 AM
Package URL
pkg:socket/skills-sh/therainstorm%2Fmy-agent-skills%2Fqb-downloader%2F@5f8cc6ea5f29f37ddd5cee3a7daf9a89b500a302