receipt-expense-workflow

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
references/receipt_sorter.py

No clear evidence of overt malware (no network exfiltration, shell execution, or credential/data theft) is present in this module’s logic. The primary security risk is handling of untrusted ZIP archives: using ZipFile.extractall(tmpdir) without validating member paths can enable ZIP Slip/path traversal or extraction-time sabotage. Secondary concerns include availability risk from unbounded OCR/PDF processing and supply-chain risk inherent to executing third-party OCR/PDF-processing dependencies (surya/pypdfium2).

Confidence: 72%Severity: 63%
Audit Metadata
Analyzed At
Aug 13, 2026, 08:22 AM
Package URL
pkg:socket/skills-sh/aktsmm%2Fagent-skills%2Freceipt-expense-workflow%2F@8ea2e0ebc02d8afd23f23728c8692d0ef69df1ef529dc8bdc9a50d6318c841d9
Security Audit — socket — receipt-expense-workflow