clips-studio

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/falvid.py

No clear, explicit malware logic is present (no dynamic code execution, backdoor, or hidden network exfiltration to unrelated domains). However, the code has two security-relevant anomalies: (1) it auto-scans CWD/home for files to extract FAL_KEY/FAL_ADMIN_KEY and injects them into environment variables, and (2) it writes downloaded video bytes to a destination path constructed from user-controlled --out-dir and --name without sanitization, enabling potential path traversal/arbitrary file overwrite. Overall, this looks like a functional but security-sensitive CLI that should be reviewed/controlled in untrusted automation contexts.

Confidence: 72%Severity: 52%
Audit Metadata
Analyzed At
Aug 27, 2026, 02:06 AM
Package URL
pkg:socket/skills-sh/moonlight-lupin%2Fagent-skills%2Fclips-studio%2F@db8526d3a4a38875e83d67f32095452f126c6512660af53c479151337a81e4d1
Security Audit — socket — clips-studio