space-video-broll

Warn

Audited by Socket on Aug 5, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/render.mjs

No direct indicators of classic malware behavior (e.g., credential theft, reverse shells, or explicit network exfiltration) are present in this module’s logic. However, the module is security-sensitive: it executes untrusted local HTML/JS in a headless Chromium instance launched with "--no-sandbox" and it executes external binaries chosen from potentially attacker-influenced locations (Chromium via CHROME_PATH/cache discovery; ffmpeg via PATH). If htmlArg and/or the runtime environment are not trusted, the risk level increases substantially. Otherwise, in a controlled rendering pipeline with trusted inputs and pinned binaries, it is likely intended as a benign HTML-to-video renderer.

Confidence: 66%Severity: 58%
Audit Metadata
Analyzed At
Aug 5, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/SpaceZephyr%2Fcreator-buddy%2Fspace-video-broll%2F@57f2f592ace7a96ec7120b2a5151e656248a0938a0643c00e63acabbdb712998
Security Audit — socket — space-video-broll