motion-broll

Warn

Audited by Socket on Sep 25, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/make_pages.py

The code appears intended to generate video review artifacts, not to perform malware-like activity. It has meaningful command-injection and generated-HTML injection risks if its paths or plan data are untrusted. Use subprocess calls with argument lists and apply context-appropriate escaping to generated HTML.

Confidence: 97%Severity: 63%
AnomalyLOW
engine/beats.js

The code appears to be a browser-based HTML screenshot and montage utility. Its main security issue is shell command injection through the unescaped output-path argument passed to execSync. Treat the HTML input as executable content and only process trusted files in a suitably isolated environment.

Confidence: 98%Severity: 67%
Audit Metadata
Analyzed At
Sep 25, 2026, 05:04 PM
Package URL
pkg:socket/skills-sh/barty-bart%2Fmotion-graphics%2Fmotion-broll%2F@f567315ce41c623e1e5b97f3d805c98f37a0c578d13e3c866b26f3d040152340
Security Audit — socket — motion-broll