ai-video-production-master

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/cloud_i2v_batch.py

The fragment appears intended for legitimate cloud-based image-to-video processing, not malware. It is currently syntactically invalid because the onstart assignment is incomplete. If repaired, it presents meaningful security risks: shell command injection through unquoted interpolated values, disabled SSH host verification, root-based remote access, and unauthenticated plaintext ComfyUI communication. Inputs and remote metadata should be validated and passed as argument arrays rather than shell strings; host-key verification, least-privilege accounts, authentication, and HTTPS should be used.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 16, 2026, 03:03 PM
Package URL
pkg:socket/skills-sh/curiositech%2Fsome_claude_skills%2Fai-video-production-master%2F@a249d09e7c5d39789611a16a615b39333057a52a9128eae80cbf008192b1b4d1
Security Audit — socket — ai-video-production-master