libtv-skill

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/upload_file.py

No explicit malware techniques are evident in the provided fragment (no obfuscation, eval/exec, persistence, or covert behavior). However, the module is a credentialed file uploader: it reads an arbitrary user-supplied local file (restricted only by MIME-prefix guessing) and transmits the entire raw bytes to a remote endpoint, redundantly sending ACCESS_KEY both as a Bearer token and as a multipart form field. Additionally, sys.path modification and reliance on a local _common module create a supply-chain/local-module trust risk. Overall, treat as a potentially sensitive network-upload tool; validate _common and the endpoint, tighten MIME/content verification, and avoid duplicating credentials.

Confidence: 65%Severity: 52%
Audit Metadata
Analyzed At
Aug 21, 2026, 02:10 AM
Package URL
pkg:socket/skills-sh/spacezephyr%2Fmyskill%2Flibtv-skill%2F@0c7a1c4b1fcd786a7008137fdf3ccb5c8a5c04caaa8e8c2c2ee4cec5c9677c8a