flow-generator
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalyreferences/media.md
LOWAnomalyLOW
references/media.md
The fragment is legitimate operational documentation for image upload and flow configuration. It contains one material security issue: using `eval` to process CLI output creates a command-injection risk if output is not strictly trusted. Replace it with safe parsing and quoted variable assignment. The documented CDN upload and approved URL download are expected side effects, while duplicate uploads create asset-management risk rather than malware.
Confidence: 98%Severity: 56%
Audit Metadata