geekmagic-smalltv-ultra

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
references/device-reference.md

No executable/package code is shown here—only documentation/specification. However, the described system design presents a high security risk: an unauthenticated HTTP interface that includes destructive operations (WiFi wipe/reset, file delete/clear, reboot/reset) and an HTTP-accessible firmware update endpoint accepting uploaded binaries. If these endpoints are network-reachable without authentication (as stated), a threat actor could persistently compromise or sabotage the device by installing malicious firmware or by deleting/wiping critical configuration. Treat this as a serious operational takeover risk rather than confirmed malware embedded in this fragment.

Confidence: 60%Severity: 78%
Audit Metadata
Analyzed At
Aug 1, 2026, 09:07 PM
Package URL
pkg:socket/skills-sh/yaniv-golan%2Fsmalltv-ultra-skill%2Fgeekmagic-smalltv-ultra%2F@cf4d06feffe2807b4d667a63e4936c30e913e636cd525194b011dba2c04dc7b0
Security Audit — socket — geekmagic-smalltv-ultra