
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
Official CLI tool to extract social video media direct links and metadata from TikTok, YouTube, Instagram, X/Twitter, and more via soclip.dev.
npm install -g soclip
Get your API key at https://soclip.dev, then configure it in your environment:
soclip config set-key <your-api-key>
Alternatively, set the SOCLIP_API_KEY environment variable:
export SOCLIP_API_KEY="your-api-key"
soclip "https://www.tiktok.com/@scout2015/video/6718335390841801990"
Output:
Title: Scout's favorite game!
Source: tiktok
Duration: 15s
Thumbnail: https://p16-sign-va.tiktokcdn.com/obj/tos-maliva-p-0068/123456789.jpg
Qualities (2):
- 1080p [1080x1920]
- 720p [720x1280]
Use --quality best|worst|<height> to get a direct link, or --json for the full response.
--quality best)soclip "https://www.tiktok.com/@scout2015/video/6718335390841801990" --quality best
Output:
https://v16-webapp-prime.tiktok.com/video/tos/useast2a/tos-useast2a-ve-0068c001/ogB...
soclip balance
Output:
Balance: 100 credits
soclip "https://www.tiktok.com/@scout2015/video/6718335390841801990" --json
1 credit = $0.001. Each successful media extraction costs 2 credits ($0.002). Credits never expire. Get started with free trial credits at https://soclip.dev.
MIT License © 2026 soclip
FAQs
TikTok / YouTube / Instagram video download API CLI — direct links and metadata. Hosted alternative to running yt-dlp yourself.
The npm package soclip-cli receives a total of 14 weekly downloads. As such, soclip-cli popularity was classified as not popular.
We found that soclip-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.