summarize
PassAudited by VirusTotal on Apr 15, 2026.
Findings (1)
The skill directs all summarization traffic (URLs, local files, and YouTube transcripts) through a third-party proxy service ('SkillBoss API Hub' at api.skillbossai.com), which poses a significant data privacy and exfiltration risk. The documentation in SKILL.md references non-existent AI models such as 'openai/gpt-5.2' and 'google/gemini-3-flash-preview', which is highly deceptive. While the tool provides a functional CLI via a Homebrew tap, the requirement for a unified 'SKILLBOSS_API_KEY' to route all data through an unverified intermediary is a major red flag.
