video

Warn

Audited by Socket on Sep 17, 2026

3 alerts found:

Anomalyx2Security
AnomalyLOW
generate_video.py

The fragment implements a video API client and does not show clear malware, persistence, data theft, or command execution. It has meaningful security weaknesses: TLS verification is disabled, traffic is routed through a plain HTTP internal proxy, a hardcoded placeholder authorization value is used, and remote URLs are followed without allowlisting or response-size validation. The unknown _cost_track helper and proxy configuration require separate review, especially because they may receive request payloads and API responses.

Confidence: 96%Severity: 68%
SecurityMEDIUM
publish_asset.py

The code appears to implement a legitimate local/media publishing utility and contains no evident malware, credential theft, or backdoor. It has significant security risks if exposed to untrusted callers: unsanitized rename values can enable path traversal or arbitrary destination writes, and unrestricted HTTP(S) fetching can enable SSRF. The URL download also permits memory exhaustion and redirects, while extension-only validation allows mislabeled content.

Confidence: 98%Severity: 78%
AnomalyLOW
poll_status.py

The code appears to be a video-generation polling and download utility rather than overt malware. It has meaningful security weaknesses: disabled TLS verification, hardcoded credential-like authorization, an unvalidated remotely supplied download URL, and unsanitized request_id use in a filesystem path. These issues warrant remediation and review of _cost_track, but the fragment contains no clear data theft, destructive behavior, or backdoor. The hardcoded key appears deliberately fake, though its presence remains unsafe practice.

Confidence: 96%Severity: 68%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fvideo%2F@e2213a41eced81eab968af3abd3f0534d24706dd1dd833461fec3f8d7bac83ef
Security Audit — socket — video