video-analyzer

Warn

Audited by Socket on Jul 30, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/analyze_video.py

No clear evidence of intentional malware/backdoor in the provided fragment, but there are significant security/supply-chain concerns: (1) yt-dlp downloads with TLS certificate verification disabled (--no-check-certificates), enabling MITM; (2) yt-dlp/ffmpeg executables are chosen via environment variables (YTDLP_PATH/FFMPEG_PATH), which could enable execution of attacker-controlled binaries if the environment is compromised; (3) the code sends base64-encoded user content (audio and frames) to OpenAI/Gemini endpoints; and (4) API keys are read from .env and Gemini keys are placed in URL query parameters. Final confidence is limited because the snippet appears truncated and the full main/analyze_video/template generation logic is not shown.

Confidence: 62%Severity: 64%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the overall workflow matches the stated video-analysis purpose and credential use is proportionate, but the skill depends on undocumented local binaries (`.bin/yt-dlp`, `.bin/ffmpeg`) whose provenance is not verifiable from the skill text. No clear malicious exfiltration or deceptive routing is shown, yet the opaque executable trust chain and transitive skill usage make it a high security-risk skill rather than a benign one.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Jul 30, 2026, 08:28 PM
Package URL
pkg:socket/skills-sh/minicoohei%2Fai-agent-camp%2Fvideo-analyzer%2F@dcce9d72b66c3dc49c6e8cec64409f6d9e8023fd180b2b8685b9219e3c28df50
Security Audit — socket — video-analyzer