github.com / calesthio
calesthio/ OpenMontage
Python·2115 files·commit cd9f3c1·scanned 16d ago·cached ✓
15/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
score capped at 15 — 51,858+ stars — findings likely false positives
verdict accurate?
51,858 stars
34% file coverage
Partial architecture graph
threat-state: lowlive
FINDINGS ░▒▓
warningPython subprocess / os.system usageos.system() or subprocess with shell=True / suspicious commands can execute arbitrary shell commands. Plain pip/package installs are usually benign.scripts/backlot_screenshot_stage.py
first_frame = pdir / "assets" / "images" / f"{scenes[0][0]}.png"
subprocess.run(["ffmpeg", "-y", "-loglevel", "error", "-loop", "1",
"-i", str(first_frame), "-t", "4", "-vf...+4warningPython subprocess / os.system usageos.system() or subprocess with shell=True / suspicious commands can execute arbitrary shell commands. Plain pip/package installs are usually benign.scripts/backlot_visual_eval.py
def run_stage() -> None:
subprocess.run(
[sys.executable, "scripts/backlot_screenshot_stage.py", "--stage-only"],
cwd=REPO_ROOT,+4warningPython subprocess / os.system usageos.system() or subprocess with shell=True / suspicious commands can execute arbitrary shell commands. Plain pip/package installs are usually benign.scripts/backlot_watch_captures.py
output.parent.mkdir(parents=True, exist_ok=True)
subprocess.run(
[
"npx",+4criticaleval() usage detectedeval() executes arbitrary code and is commonly used in malware to run obfuscated payloads fetched from remote servers.tools/graphics/math_animate.py
elif isinstance(node, ast.Name):
# Blocks direct calls (eval(...)) and indirection alike:
# `__builtins__['open']`, `f = open`, `getattr(o, '__class__')`.
...+8warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.ink-theater/mocap/clips/climb.json+4
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.ink-theater/mocap/clips/dance_glide.json+4
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.ink-theater/mocap/clips/dance_spin.json+4
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order..agents/skills/hyperframes-animation/scripts/animation-map.mjs+3
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode..agents/skills/hyperframes-animation/scripts/package-loader.mjs+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order..agents/skills/hyperframes-animation/scripts/package-loader.mjs+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order..agents/skills/hyperframes-creative/scripts/contrast-report.mjs+3
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode..agents/skills/hyperframes-creative/scripts/extract-audio-data.py+3
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode..agents/skills/hyperframes-creative/scripts/package-loader.mjs+3
infoSuspicious file in repoVery large source file (528KB) — could contain obfuscated payloadink-theater/examples/mocap-figure/clips.js+2
infoSuspicious file in repoVery large source file (528KB) — could contain obfuscated payloadink-theater/mocap/clips.js+2
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
709 files scanned @ cd9f3c1 | 8/27/2026 | heuristic scan — always review manually
risk by category
code execution25
network & exfiltration0
file system access0
obfuscation15
supply chain4
owasp / injection0
telemetry
files 709/2115rules hit 16engine v5commit cd9f3c1
github
calesthio/OpenMontage
World's first open-source, agentic video production system. 12 production pipelines, 100+ tools, 700+ agent skill and production-knowledge files. Turn your AI coding assistant into a full video production studio.
51858
6508
167d
2115 files
709 scanned(34%)
cd9f3c1
architecture░▒▓
entry (0) flagged (92) pkg (157)
557 nodes · 1252 edgesscroll to zoom · click node to jump to finding