alibabacloud-media-diagnostics

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/hls_check.py

The code appears intended for HLS stream diagnostics and contains no clear malware, backdoor, credential theft, persistence, or destructive behavior. It does contain potentially dangerous input-to-network and input-to-filesystem flows: arbitrary playlist and segment URLs can trigger outbound requests, and non-URL/file:// inputs can read arbitrary local files. These risks matter primarily when invoked with untrusted input. The supplied fragment is syntactically invalid as written and would require correction before execution.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Aug 27, 2026, 07:46 AM
Package URL
pkg:socket/skills-sh/aliyun%2Falibabacloud-aiops-skills%2Falibabacloud-media-diagnostics%2F@b4d205673121684e90cf86fd777eef144ab1bf0e1e55d27ab7bc91f76f553de1
Security Audit — socket — alibabacloud-media-diagnostics