remotion-to-hyperframes

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/test-corpus/run.sh

No explicit malicious behavior (exfiltration, backdoor indicators, hardcoded credentials, obvious obfuscated payloads) is present in this Bash orchestrator file. However, it substantially increases supply-chain and host-execution exposure by (1) executing fixture-provided setup.sh and validate.sh with no sandboxing and (2) performing runtime npm install inside fixture directories without visible pinning/integrity controls. Treat fixtures and dependency provenance as high trust or add sandboxing, pinning, and integrity verification to reduce risk.

Confidence: 63%Severity: 60%
Audit Metadata
Analyzed At
May 9, 2026, 05:19 AM
Package URL
pkg:socket/skills-sh/heygen-com%2Fhyperframes%2Fremotion-to-hyperframes%2F@b40d286e05c98cfebb3a88127405ff37e2c14338