mineru-extract

Warn

Audited by Socket on Oct 9, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/mineru_parse_documents.py

The code appears intended to automate MinerU document extraction and contains no evident malware. The main security concerns are unsafe extraction of a remotely supplied ZIP archive and fetching an API-provided URL without destination validation. The API token is also exposed if the configurable API base is untrusted.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Oct 9, 2026, 01:44 PM
Package URL
pkg:socket/skills-sh/blessonism%2Fopenclaw-skills%2Fmineru-extract%2F@fce878cb13b0122c20069c83c82289304c6cad584d8633fcd08fc58bf179049b