ai-multimodal

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/media_optimizer.py

Overall, this looks like a legitimate media optimization/transcoding utility (no network/persistence/exfiltration logic visible). The primary security concern is a direct eval() on ffprobe-derived metadata (r_frame_rate), creating a potential arbitrary code execution risk if attacker-controlled media can influence that field into executable Python. Additional concerns are side-effectful .env loading at import time and reliance on external ffmpeg/ffprobe for processing untrusted files.

Confidence: 66%Severity: 68%
AnomalyLOW
scripts/document_converter.py

No strong indicators of embedded malware (backdoor, obfuscated payloads, command execution, credential theft, or covert networking) are present in the provided fragment. The dominant security concern is privacy/data exfiltration by design: the tool uploads or transmits user-supplied local documents to the Google Gemini service and writes the generated output to disk. Additional operational risks include loading .env files from multiple directories and allowing arbitrary input/output paths without validation. Treat this as a sensitive-data-handling utility and review/confirm the missing/incomplete lines in the snippet before use.

Confidence: 52%Severity: 55%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:10 PM
Package URL
pkg:socket/skills-sh/mrgoonie%2Fclaudekit-skills%2Fai-multimodal%2F@2711e3914dfeb7485b0a8bbfacdec7bb305a87b81eafad09e9332bdf522b1c8d
Security Audit — socket — ai-multimodal