add-sfx

Warn

Audited by Socket on Jun 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/pull-library.sh

This module is an automated CDN-backed asset downloader, not an obvious standalone malware component. However, it has a meaningful supply-chain security weakness: an untrusted remote catalog directly influences the filesystem write destination via catalog.sounds[*].file, with no enforcement that writes remain within the intended LIB_DIR (absolute paths and traversal-like segments are plausible). It also lacks checksum/signature verification for downloaded content. If the CDN/catalog can be tampered with, this could enable overwriting arbitrary files on the host running the script.

Confidence: 72%Severity: 65%
Audit Metadata
Analyzed At
Jun 29, 2026, 03:19 AM
Package URL
pkg:socket/skills-sh/woven-video%2Fskills%2Fadd-sfx%2F@74d7fec0149b275c7d3a9b0fe0753b921888ff71b36293ab072c1e7ce43935d2
Security Audit — socket — add-sfx