manimate

Warn

Audited by Socket on Mar 6, 2026

1 alert found:

Anomaly
AnomalyLOW
bin/postinstall.js

The script simply runs a bundled install.sh using bash. The JS is not itself obfuscated or directly malicious, but executing a packaged shell script without integrity checks is a meaningful supply-chain risk: if install.sh is malicious or tampered with, arbitrary code will run on the host. Audit the install.sh contents and the package publishing process before trusting this package.

Confidence: 80%Severity: 50%
Audit Metadata
Analyzed At
Mar 6, 2026, 09:00 PM
Package URL
pkg:socket/skills-sh/bassimeledath%2Fmanim-video-maker%2Fmanimate%2F@9cb280b7c1ab464052b0ed10c834efb5160497cc