amc-run-video-calibration

Warn

Audited by Socket on Aug 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run_video_calibration.py

No explicit malware primitives (exec/eval, shell commands, persistence) are present in this module. However, the script is highly capable of uploading local sensitive artifacts (videos/config/alignment/layout/GT zip) to an endpoint controlled by the environment variable BASE_URL. Without domain allowlisting and with defaultable/overridable networking (including potential plain HTTP), this presents a credible supply-chain/data-exfiltration risk if used in an untrusted context or if BASE_URL/VOLUME paths are tampered with.

Confidence: 62%Severity: 63%
Audit Metadata
Analyzed At
Aug 16, 2026, 05:54 PM
Package URL
pkg:socket/skills-sh/nvidia%2Fdeepstream%2Famc-run-video-calibration%2F@ff26254679b8493d78600dfa6a5396397bd6d2753a92a6078c971eead7ec97d6
Security Audit — socket — amc-run-video-calibration