acestep-thumbnail

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/acestep-thumbnail.sh

The code is primarily a legitimate Gemini thumbnail-generation utility. No clear malware or covert malicious behavior is present. Security concerns include unrestricted api_url configuration that can exfiltrate the API key and prompt, API-key placement in the URL, jq filter injection through the user-controlled configuration key, and arbitrary user-permitted file writes through --output. These issues should be addressed with an allowlist for configuration keys, validation/pinning of the API host and scheme, safer secret transmission where supported, and output-path restrictions. The findings indicate security weaknesses but not intentional malware in this fragment.

Confidence: 97%Severity: 55%
Audit Metadata
Analyzed At
Sep 18, 2026, 05:26 PM
Package URL
pkg:socket/skills-sh/ace-step%2Face-step-1.5%2Facestep-thumbnail%2F@81d56266ce0253a976371b03625eb5a05bf16d1d2ebc4f1e54f749eaa8c6a3e3
Security Audit — socket — acestep-thumbnail