upload-r2
Fail
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: Accesses a sensitive configuration file at a hardcoded local path:
/Users/jonathanburger/remotion/packages/remotion-media/.env. This file is explicitly identified as containingAWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEYcredentials. - [COMMAND_EXECUTION]: Utilizes the
bunruntime to execute an inline JavaScript script via the-eflag, which performs file operations and S3 uploads using credentials loaded from the local environment file. - [COMMAND_EXECUTION]: Executes system shell commands including
git worktree listandcurl -Ito manage local repository paths and verify remote asset hosting status.
Recommendations
- AI detected serious security threats
Audit Metadata