plotting-agent
Warn
Audited by Socket on Sep 28, 2026
1 alert found:
AnomalyAnomalyscripts/paperbanana_render.py
LOWAnomalyLOW
scripts/paperbanana_render.py
This module is primarily a figure-generation CLI/orchestrator. It does not show overt malware (no exec/subprocess/network activity in the fragment). The principal security risk is supply-chain/local code execution: PAPERBANANA_PATH is used to prepend sys.path and import backend and agent modules from that directory without integrity checks. The module also decodes and parses untrusted base64 image data using Pillow and writes it to a user-specified output path, which is a secondary risk area typical for image renderers.
Confidence: 68%Severity: 55%
Audit Metadata