byted-mediakit-voiceover-editing

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/review-page/index.html

No clear evidence of intentional malware/backdoor behavior is present in the shown fragment. The main security concern is privacy/data exfiltration risk: callExport() POSTs the full project payload to an arbitrary user-controlled URL (service-url) without visible origin/allowlist validation. Additionally, imported JSON is only loosely validated and is propagated into export/save payloads, and extensive console logging may expose sensitive project content in the client environment. Review surrounding app context (how service-url is set/influenced) and implement URL allowlisting plus stricter import schema validation and reduced debug logging.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
May 4, 2026, 03:25 AM
Package URL
pkg:socket/skills-sh/bytedance%2Fagentkit-samples%2Fbyted-mediakit-voiceover-editing%2F@e91974d7b517b1b2f581894efcc25ae96b2d272d