libtv-skill
Audited by Socket on Aug 21, 2026
1 alert found:
AnomalyNo explicit malware techniques are evident in the provided fragment (no obfuscation, eval/exec, persistence, or covert behavior). However, the module is a credentialed file uploader: it reads an arbitrary user-supplied local file (restricted only by MIME-prefix guessing) and transmits the entire raw bytes to a remote endpoint, redundantly sending ACCESS_KEY both as a Bearer token and as a multipart form field. Additionally, sys.path modification and reliance on a local _common module create a supply-chain/local-module trust risk. Overall, treat as a potentially sensitive network-upload tool; validate _common and the endpoint, tighten MIME/content verification, and avoid duplicating credentials.