fill-icmje-coi

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/fill_icmje_coi.py

The code appears to be a legitimate DOCX form-generation utility and contains no evident malware or supply-chain backdoor. It has a moderate path traversal and arbitrary file-write risk because author-controlled text contributes directly to the output filename without safe-path validation. Sanitize filenames to a strict allowlist and verify the resolved output path remains inside out_dir before writing.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Sep 17, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/aperivue%2Fmedsci-skills%2Ffill-icmje-coi%2F@f2c27ff6f8806e0661c9793edd1763295bc880ed901221e572ff0a58b3f763f2
Security Audit — socket — fill-icmje-coi