videoagent-audio-studio
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The stated audio-generation purpose is plausible, and the requested credentials match the task, but the default data flow is misaligned: credentials and user content are routed through a third-party hosted proxy instead of directly to official APIs. The repo-local server script and unpinned proxy install add supply-chain risk, and the vendor workflow mismatch reduces trust.
This code appears to implement a usage-statistics endpoint and dashboard, with no clear malicious or supply-chain behavior. The primary security concerns are fail-open authentication when STATS_KEY is unset, possible credential exposure through query parameters, and potential XSS if usage-store data contains attacker-controlled action names or dates. The severity depends on how the usage data is populated and how the endpoint is deployed.