video-podcast-maker

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/tts/backends/ttscn.py

This fragment does not show direct malware behavior (no network activity, no persistence, no obvious data theft). However, it carries moderate security risk because it executes a configurable external Python entrypoint (config['entry']) and passes through inherited environment variables, while also performing filesystem writes/deletes under output_dir. If an attacker can influence configuration values (especially entry, output_dir, or environment), they could potentially achieve arbitrary code execution and unintended filesystem impact. Otherwise, with trusted configuration, it appears consistent with a legitimate TTS + ffmpeg audio synthesis pipeline.

Confidence: 62%Severity: 50%
Audit Metadata
Analyzed At
Aug 1, 2026, 10:50 AM
Package URL
pkg:socket/skills-sh/Agents365-ai%2F365-skills%2Fvideo-podcast-maker%2F@1783721d0c2d7b389f69b7763c50b74cc6a01fb8b847448023dda1b70efede6c
Security Audit — socket — video-podcast-maker