ai-multimodal

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/media_optimizer.py

Overall, this looks like a legitimate media optimization/transcoding utility (no network/persistence/exfiltration logic visible). The primary security concern is a direct eval() on ffprobe-derived metadata (r_frame_rate), creating a potential arbitrary code execution risk if attacker-controlled media can influence that field into executable Python. Additional concerns are side-effectful .env loading at import time and reliance on external ffmpeg/ffprobe for processing untrusted files.

Confidence: 66%Severity: 68%
AnomalyLOW
scripts/document_converter.py

No strong indicators of embedded malware (backdoor, obfuscated payloads, command execution, credential theft, or covert networking) are present in the provided fragment. The dominant security concern is privacy/data exfiltration by design: the tool uploads or transmits user-supplied local documents to the Google Gemini service and writes the generated output to disk. Additional operational risks include loading .env files from multiple directories and allowing arbitrary input/output paths without validation. Treat this as a sensitive-data-handling utility and review/confirm the missing/incomplete lines in the snippet before use.

Confidence: 52%Severity: 55%
Audit Metadata
Analyzed At
Sep 16, 2026, 08:38 PM
Package URL
pkg:socket/skills-sh/duc01226%2Finvestment%2Fai-multimodal%2F@db9be817c325b6d44c59b13437ec3e7603f98cecef6caf4a3bc7b9fb2716e4ea
Security Audit — socket — ai-multimodal