civitai-gen

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
experiment.mjs

No direct malware behavior is evident in this module (no eval/obfuscation, no network calls, no reverse shell patterns). However, it enables security-relevant misuse by providing an arbitrary local file read primitive through --save-wildcard '@<path>' and by passing untrusted, user-controlled prompt/spec data into a spawned generate.mjs process. These behaviors warrant review of generate.mjs and addition of strict path/filename containment and input validation controls in this wrapper.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 08:47 PM
Package URL
pkg:socket/skills-sh/civitai%2Fcivitai-gen-skill%2Fcivitai-gen%2F@ea87f07663ad74d0bba85985921287f2d4cb8aa3c532a1c905b8c4a6638cbfb4
Security Audit — socket — civitai-gen