desktop-packaging-tauri

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/core.md

No explicit malware or obfuscation is evident in the provided fragment. However, the command creates a meaningful security attack surface: untrusted `input` is passed directly to an external ffmpeg sidecar as the `-i` argument, and the resulting stdout/stderr (often path- and environment-revealing) is returned to the caller. Additionally, a fixed `output.mp4` name can cause overwrite/collision issues. Treat this as a security-relevant component requiring input validation and execution sandboxing/permission tightening (e.g., capability restrictions, allowlisted input sources, isolated output paths).

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Jul 25, 2026, 02:35 AM
Package URL
pkg:socket/skills-sh/agents-inc%2Fskills%2Fdesktop-packaging-tauri%2F@1e7ef4943ecf1be4cbfaa60dc02e397b25d55a150b66ef34b3e1350a189601f9
Security Audit — socket — desktop-packaging-tauri