cesto-creator-toolkit

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/_store.py

No clear malicious behavior or exfiltration is present. The code implements local session-token storage, but its XOR/Base85 protection is cryptographically weak and should be replaced with authenticated encryption or a platform credential store. File writes should use safer atomic and symlink-resistant handling. The fragment also appears to contain a missing closing parenthesis at the end.

Confidence: 98%Severity: 55%
SecurityMEDIUM
scripts/api_request.py

The code appears intended to be an authenticated API request wrapper, not overt malware. However, the URL allowlist is vulnerable to hostname-prefix bypasses. An attacker able to control the URL argument can cause the stored bearer token, and potentially request data, to be sent to an unauthorized domain such as backend.cesto.co.evil. The check should parse the URL and require an exact hostname and HTTPS scheme, with appropriate port restrictions. The issue is a significant credential-exfiltration risk in contexts where untrusted callers can invoke the script.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:19 AM
Package URL
pkg:socket/skills-sh/cesto-co%2Fcesto-skills%2Fcesto-creator-toolkit%2F@2807b1ec56952f17aa72154b103861613677b5eed8c35a5c9a2a106f4cdf0305
Security Audit — socket — cesto-creator-toolkit