streamdeck-lab

Fail

Audited by Socket on Mar 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
bridge.py

This file is a functional UI-to-tooling bridge and is not itself containing obfuscated or overtly malicious code. The primary security risk is delegation: it executes a local run.sh wrapper and imports a local package in a subprocess, creating a supply-chain/local-tampering execution vector. Persisting UI-provided JSON to repository files without schema validation increases integrity risk. Recommend treating run.sh and the local streamdeck_lab package as high-risk assets: verify their integrity, reduce privileges of subprocesses, and add validation/sandboxing.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:42 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fstreamdeck-lab%2F@f00ec1fc5b74cb9d16dd6ab449016756858bfb03
Security Audit — socket — streamdeck-lab