amc-run-video-calibration

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run_video_calibration.py

No clear evidence of embedded malware (no obfuscation, no eval/exec, no process/system command execution, no credential theft). However, the module can perform significant data exfiltration because it uploads arbitrary local files (videos and optional config/alignment/layout/GT zip) to a destination URL entirely determined by the BASE_URL environment variable. If BASE_URL is attacker-controlled, this becomes a high-impact exfiltration vector. Otherwise, in a trusted environment it appears to be a normal remote calibration orchestration script.

Confidence: 66%Severity: 55%
Audit Metadata
Analyzed At
Jul 15, 2026, 10:05 AM
Package URL
pkg:socket/skills-sh/NVIDIA%2Fskills%2Famc-run-video-calibration%2F@3bd55220015b5d4ee1461a6ac50ee15f85cc9b7563f3f848f48fd5cd42f690ac
Security Audit — socket — amc-run-video-calibration