tts-train
Audited by Socket on Aug 26, 2026
1 alert found:
Obfuscated FileThe inspected module itself does not contain explicit malware artifacts (no hardcoded credentials, no network exfiltration calls), so active malicious intent inside this file appears unlikely. However, it provides powerful primitives for arbitrary code execution: unvalidated subprocess invocations (run.sh, training scripts) and an inline python -c built from user-controlled strings. These are genuine command/code injection and supply-chain risks: if an attacker can control CLI arguments or replace expected local scripts/files, they can execute arbitrary code and manipulate model artifacts. Treat this module as moderate-to-high security risk in hostile environments; hardening and sanitization are required before use in multi-tenant or untrusted settings.