registry  /  mediasnacks  /  0.30.1

mediasnacks@0.30.1

Utilities for optimizing and preparing videos and images

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis flagged 8 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoDynamicRequireEvalFilesystemShell
Supply chain
UrlStrings
ManifestNo manifest risk signals triggered.
scanned 33 file(s), 47.1 KB of source, external domains: trac.ffmpeg.org, wiki.avblocks.com

Source & flagged code

4 flagged · loading source
package.jsonView file
scripts.postinstall = node install-zsh-completions.js
High
Install Time Lifecycle Scripts

Package defines install-time lifecycle scripts.

package.jsonView on unpkg
src/edgespic.jsView file
56'-y', L57: '-sseof', -1 / eval(r_frame_rate), L58: '-i', video,
Low
Eval

Package source references a known benign dynamic code generation pattern.

src/edgespic.jsView on unpkg · L56
src/cli.jsView file
80if (cmd.endsWith('.js')) L81: await (await import(cmd)).default() L82: else
Medium
Dynamic Require

Package source references dynamic require/import behavior.

src/cli.jsView on unpkg · L80
src/vdiff.shView file
path = src/vdiff.sh kind = build_helper sizeBytes = 742 magicHex = [redacted]
Medium
Ships Build Helper

Package ships non-JavaScript build or shell helper files.

src/vdiff.shView on unpkg

Findings

1 High3 Medium4 Low
HighInstall Time Lifecycle Scriptspackage.json
MediumDynamic Requiresrc/cli.js
MediumShips Build Helpersrc/vdiff.sh
MediumStructural Risk Force Deep Review
LowScripts Present
LowEvalsrc/edgespic.js
LowFilesystem
LowUrl Strings