lightx2v

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/lightx2v_submit_and_poll.sh

This script is a straightforward client that uploads user-specified media (or URLs) and submits tasks to a remote LightX2V API, polling for results. It does not contain obfuscated or clearly malicious code. However, it has a significant data-exfiltration capability by design: local files passed as arguments (or referenced via config) are base64-encoded and sent to the configured remote server, and stored tokens from a local config can be automatically exported and used. That behavior is expected for a cloud client but poses a security risk if users accidentally supply sensitive files or if BASE_URL/TOKEN are set to an attacker-controlled server. Recommend auditing where tokens come from, validating BASE_URL before use, and warning users about uploading sensitive files.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 11, 2026, 06:40 AM
Package URL
pkg:socket/skills-sh/xinyiqin%2FX2V-AI-Images-Videos-skill%2Flightx2v%2F@77e3493e7c8a98fe2c875a9d187b030acc4725fc