Caveat verdict

ai-subtitle-remover

550w-ai-subtitle-remover

88
🟢 Trusted
No high-risk patterns surfaced by the deep scan — automated capability review, not behavioral proof.

Describes a tool that calls an external subtitle‑removal service using provided credentials, which is a normal network operation.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

95
security
90
transparency
80
maintenance

Findings (2)

Pattern match low

Popular HTTP library — network access

dist/api-client.js · prose · downgraded · axios

Pattern match low

Accesses sensitive environment variables

dist/credential-manager.js · prose · downgraded · process.env.SUBTITLE_REMOVER_API_KEY

Permissions & capabilities

Requires 2 environment variables. (1 sensitive: SUBTITLE_REMOVER_API_KEY).

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API