voice-segment-selector
Audited by Socket on Aug 26, 2026
2 alerts found:
Anomalyx2The code implements an audio/transcript review tool and contains no clear malware or supply-chain payload. The main risks are an unauthenticated state-changing API when exposed beyond localhost, incomplete path containment checks, reliance on PATH for ffmpeg, and a potential DOM-XSS issue from inserting candidate IDs into innerHTML. These are security weaknesses requiring remediation but do not by themselves indicate malicious intent.
The fragment appears to be a legitimate local audio dataset exporter, not malware. It contains a moderate security concern because untrusted candidate metadata can influence filesystem reads and output paths without containment or filename sanitization. It also contains a clear implementation error in _write_orpheus_lora_config() that can break exports. Validate paths with resolve()/commonpath checks, restrict source files to job_dir, sanitize speaker and id, and fix the undefined card_path and limitations references before use.