amc-run-video-calibration
Warn
Audited by Socket on Aug 16, 2026
1 alert found:
AnomalyAnomalyscripts/run_video_calibration.py
LOWAnomalyLOW
scripts/run_video_calibration.py
No explicit malware primitives (exec/eval, shell commands, persistence) are present in this module. However, the script is highly capable of uploading local sensitive artifacts (videos/config/alignment/layout/GT zip) to an endpoint controlled by the environment variable BASE_URL. Without domain allowlisting and with defaultable/overridable networking (including potential plain HTTP), this presents a credible supply-chain/data-exfiltration risk if used in an untrusted context or if BASE_URL/VOLUME paths are tampered with.
Confidence: 62%Severity: 63%
Audit Metadata