huashu-design

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/cloud/ai-review-video.py

No evidence of overt malware/backdoor behavior is present in this module. However, the code intentionally performs authenticated off-host transmission of user-provided video content (base64 data URLs) and structured prompt/context (including optional director context and derived timeline metadata) to a hardcoded third-party AI API, then persists the remote output locally in a markdown report. This creates a substantial privacy and supply-chain operational risk if users/teams do not explicitly consent to external disclosure and data retention. Additionally, the snippet shows CHECKLIST/SEVERITY_RULE placeholders, which could indicate the provided fragment may be incomplete and reduces confidence in exact runtime behavior.

Confidence: 66%Severity: 64%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:05 PM
Package URL
pkg:socket/skills-sh/mxyhi%2Fok-skills%2Fhuashu-design%2F@52ac1a38006a1e8f1257e305e17ae53be55b5d6842debffb110c23f0bd32b66a
Security Audit — socket — huashu-design