ai-multimodal
Audited by Socket on Sep 14, 2026
2 alerts found:
Anomalyx2Overall, this looks like a legitimate media optimization/transcoding utility (no network/persistence/exfiltration logic visible). The primary security concern is a direct eval() on ffprobe-derived metadata (r_frame_rate), creating a potential arbitrary code execution risk if attacker-controlled media can influence that field into executable Python. Additional concerns are side-effectful .env loading at import time and reliance on external ffmpeg/ffprobe for processing untrusted files.
No strong indicators of embedded malware (backdoor, obfuscated payloads, command execution, credential theft, or covert networking) are present in the provided fragment. The dominant security concern is privacy/data exfiltration by design: the tool uploads or transmits user-supplied local documents to the Google Gemini service and writes the generated output to disk. Additional operational risks include loading .env files from multiple directories and allowing arbitrary input/output paths without validation. Treat this as a sensitive-data-handling utility and review/confirm the missing/incomplete lines in the snippet before use.