ai-video-production-master
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecurityscripts/cloud_i2v_batch.py
MEDIUMSecurityMEDIUM
scripts/cloud_i2v_batch.py
The fragment appears intended for legitimate cloud-based image-to-video processing, not malware. It is currently syntactically invalid because the onstart assignment is incomplete. If repaired, it presents meaningful security risks: shell command injection through unquoted interpolated values, disabled SSH host verification, root-based remote access, and unauthenticated plaintext ComfyUI communication. Inputs and remote metadata should be validated and passed as argument arrays rather than shell strings; host-key verification, least-privilege accounts, authentication, and HTTPS should be used.
Confidence: 98%Severity: 72%
Audit Metadata