pdf

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Security
SecurityMEDIUM
examples/invoice-generator.md

The fragment is an invoice PDF generator with one critical security issue: eval(row['items']) permits arbitrary code execution from a malicious or tampered CSV. It should be replaced with a safe parser such as ast.literal_eval for trusted Python-literal formats or, preferably, JSON parsing with schema validation. The invoice_number used in output filenames should also be restricted to a safe filename format and verified to remain within output_dir. The shown code does not otherwise indicate malware or intentional sabotage.

Confidence: 98%Severity: 86%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:22 PM
Package URL
pkg:socket/skills-sh/autumnsgrove%2Fclaudeskills%2Fpdf%2F@0a7b7dc4e67480a2ac327ef47bab8bb841a11f7dd873da8faf2f70af9aa8041e
Security Audit — socket — pdf