streamdeck-lab
Fail
Audited by Socket on Mar 17, 2026
1 alert found:
Obfuscated FileObfuscated Filebridge.py
HIGHObfuscated FileHIGH
bridge.py
This file is a functional UI-to-tooling bridge and is not itself containing obfuscated or overtly malicious code. The primary security risk is delegation: it executes a local run.sh wrapper and imports a local package in a subprocess, creating a supply-chain/local-tampering execution vector. Persisting UI-provided JSON to repository files without schema validation increases integrity risk. Recommend treating run.sh and the local streamdeck_lab package as high-risk assets: verify their integrity, reduce privileges of subprocesses, and add validation/sandboxing.
Confidence: 98%
Audit Metadata