The skill’s video transcription purpose is clear, but its helper script can turn a user-supplied prompt or crafted environment path into local Python code execution.
Review before installing. Only use this skill with trusted prompt text and trusted environment paths, because a crafted prompt or path could execute local Python code. Prefer a fixed version that calls Whisper directly or passes inputs through safe structured arguments instead of generating python -c source. Also confirm where videos and model files will be stored, and avoid the optional global yt-dlp config unless you want it to apply beyond this skill.