mineru-extract
Warn
Audited by Socket on Oct 9, 2026
1 alert found:
AnomalyAnomalyscripts/mineru_parse_documents.py
LOWAnomalyLOW
scripts/mineru_parse_documents.py
The code appears intended to automate MinerU document extraction and contains no evident malware. The main security concerns are unsafe extraction of a remotely supplied ZIP archive and fetching an API-provided URL without destination validation. The API token is also exposed if the configurable API base is untrusted.
Confidence: 98%Severity: 62%
Audit Metadata