remotion-to-hyperframes

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/test-corpus/run.sh

No explicit malicious behavior (exfiltration, backdoor indicators, hardcoded credentials, obvious obfuscated payloads) is present in this Bash orchestrator file. However, it substantially increases supply-chain and host-execution exposure by (1) executing fixture-provided setup.sh and validate.sh with no sandboxing and (2) performing runtime npm install inside fixture directories without visible pinning/integrity controls. Treat fixtures and dependency provenance as high trust or add sandboxing, pinning, and integrity verification to reduce risk.

Confidence: 63%Severity: 60%
Audit Metadata
Analyzed At
May 11, 2026, 12:09 PM
Package URL
pkg:socket/skills-sh/marclelamy%2FSKILLS%2Fremotion-to-hyperframes%2F@4011db289fe87eb168186dc0286553859730886b
Security Audit — socket — remotion-to-hyperframes