remotion-to-hyperframes
Warn
Audited by Socket on May 9, 2026
1 alert found:
AnomalyAnomalyassets/test-corpus/run.sh
LOWAnomalyLOW
assets/test-corpus/run.sh
No explicit malicious behavior (exfiltration, backdoor indicators, hardcoded credentials, obvious obfuscated payloads) is present in this Bash orchestrator file. However, it substantially increases supply-chain and host-execution exposure by (1) executing fixture-provided setup.sh and validate.sh with no sandboxing and (2) performing runtime npm install inside fixture directories without visible pinning/integrity controls. Treat fixtures and dependency provenance as high trust or add sandboxing, pinning, and integrity verification to reduce risk.
Confidence: 63%Severity: 60%
Audit Metadata