plotting-agent

Warn

Audited by Socket on Sep 28, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/paperbanana_render.py

This module is primarily a figure-generation CLI/orchestrator. It does not show overt malware (no exec/subprocess/network activity in the fragment). The principal security risk is supply-chain/local code execution: PAPERBANANA_PATH is used to prepend sys.path and import backend and agent modules from that directory without integrity checks. The module also decodes and parses untrusted base64 image data using Pillow and writes it to a user-specified output path, which is a secondary risk area typical for image renderers.

Confidence: 68%Severity: 55%
Audit Metadata
Analyzed At
Sep 28, 2026, 01:44 AM
Package URL
pkg:socket/skills-sh/ar9av%2Fpaperorchestra%2Fplotting-agent%2F@ff7801db6c8aa4a5a898f34fbaa16177251ec8b6e3ca86bb265aff778c78f77b
Security Audit — socket — plotting-agent