motion-broll
Warn
Audited by Socket on Sep 25, 2026
2 alerts found:
Anomalyx2Anomalyscripts/make_pages.py
LOWAnomalyLOW
scripts/make_pages.py
The code appears intended to generate video review artifacts, not to perform malware-like activity. It has meaningful command-injection and generated-HTML injection risks if its paths or plan data are untrusted. Use subprocess calls with argument lists and apply context-appropriate escaping to generated HTML.
Confidence: 97%Severity: 63%
Anomalyengine/beats.js
LOWAnomalyLOW
engine/beats.js
The code appears to be a browser-based HTML screenshot and montage utility. Its main security issue is shell command injection through the unescaped output-path argument passed to execSync. Treat the HTML input as executable content and only process trusted files in a suitably isolated environment.
Confidence: 98%Severity: 67%
Audit Metadata