Open Omni — grab any video from YouTube, X, Instagram, Threads & 1800+ sites — right from your terminal. paste. download. done.
A user-run media-download command can retrieve and execute third-party downloader binaries without a pinned version, signature, or checksum verification. This is a supply-chain remote-code-execution capability, but it is not activated during npm installation.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli.jsView on unpkg · L12Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cli.jsView on unpkg · L1093The CLI fetches the latest yt-dlp executable, makes it executable, and stores it in the user's home directory without an integrity check.
dist/cli.jsView on unpkg · L1025The fetched yt-dlp path is passed directly to a child process for execution.
dist/cli.jsView on unpkg · L1236This report applies to open-omni@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli.jsView on unpkg · L12The CLI fetches the latest yt-dlp executable, makes it executable, and stores it in the user's home directory without an integrity check.
dist/cli.jsView on unpkg · L1025Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cli.jsView on unpkg · L1093The fetched yt-dlp path is passed directly to a child process for execution.
dist/cli.jsView on unpkg · L1236