camsnap

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill documentation describes a legitimate local camera capture tool that uses ffmpeg/ffprobe and stores credentials locally. There is no evidence of remote exfiltration, obfuscated code, or third-party credential forwarding. The main security concern is credential management: passwords are stored base64-encoded in ~/.camsnap_credentials (no encryption) and many examples embed credentials directly in RTSP URLs or shell scripts, which risks leaking secrets via process lists, shell history, or backups. Operational guidance should be strengthened: avoid embedding credentials in command lines, use secure secret stores or OS-level keyrings, encrypt credentials at rest, and document secure notification/transfer channels for alerts/artifacts. Overall, I assess low probability of intentional malicious behavior but moderate security risk due to weak credential handling and example patterns that encourage insecure usage.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:12 AM
Package URL
pkg:socket/skills-sh/winsorllc%2Fupgraded-carnival%2Fcamsnap%2F@31f6ce5115a1da2f8d5190fe02cf38f848e78e2e