q-multimodal

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/gemini/batch/utils.py

No clear evidence of overt malware (no obfuscation, no backdoor/persistence, no subprocesses, no keylogging/clipboard theft). However, the code dynamically imports and executes pipeline_config.py from an environment-controlled path (exec_module), which is an arbitrary code execution/supply-chain risk if the config file/path can be tampered with. Additionally, the module intentionally uploads media/prompt content to Google Gemini, which is expected for the pipeline but represents network data transmission.

Confidence: 68%Severity: 52%
Audit Metadata
Analyzed At
Jul 21, 2026, 10:20 AM
Package URL
pkg:socket/skills-sh/TyrealQ%2Fq-skills%2Fq-multimodal%2F@bb7cf41da3506aff3cdc0e774b3a1d7a4f322df8485823d7f745a4684b1d5631
Security Audit — socket — q-multimodal