voice-segment-selector

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/lib/review.py

The code implements an audio/transcript review tool and contains no clear malware or supply-chain payload. The main risks are an unauthenticated state-changing API when exposed beyond localhost, incomplete path containment checks, reliance on PATH for ffmpeg, and a potential DOM-XSS issue from inserting candidate IDs into innerHTML. These are security weaknesses requiring remediation but do not by themselves indicate malicious intent.

Confidence: 97%Severity: 58%
AnomalyLOW
scripts/lib/export.py

The fragment appears to be a legitimate local audio dataset exporter, not malware. It contains a moderate security concern because untrusted candidate metadata can influence filesystem reads and output paths without containment or filename sanitization. It also contains a clear implementation error in _write_orpheus_lora_config() that can break exports. Validate paths with resolve()/commonpath checks, restrict source files to job_dir, sanitize speaker and id, and fix the undefined card_path and limitations references before use.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:03 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fvoice-segment-selector%2F@940a7e85989c049f946fa2fc9c2ca1d5f78dbb7dbf6368950e02a89eac0c5586
Security Audit — socket — voice-segment-selector