touchdesigner
Fail
Audited by Snyk on Jun 19, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This bundle exposes an unauthenticated local HTTP API that accepts POST /execute and runs arbitrary Python via exec() in the TouchDesigner process (allowing remote code execution and access to project internals), which is a high-risk backdoor enabling RCE and potential data exfiltration if the port is reachable.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata