video-analysis

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
_postplus_shared/00-core/shared-runtime/scripts/lib/hosted_media_generation_bridge.mjs

No clear evidence of intentional malware/backdoor behavior is present in this module alone. However, it provides powerful capabilities: it can read arbitrary local files (via resolved localFilePath) and write arbitrary files (via resolved outputPath) using remote-provided base64 content, with minimal validation/containment. If upstream callers or the bridge supply untrusted paths/urls/content, this can enable data exfiltration (upload) and unintended file overwrite or persistence-like impact (download).

Confidence: 62%Severity: 63%
Audit Metadata
Analyzed At
May 5, 2026, 05:07 PM
Package URL
pkg:socket/skills-sh/PostPlusAI%2Fpostplus-skills%2Fvideo-analysis%2F@06c0f59dfbdc439e1828c26348938e8aa291b1a2