longform-to-content

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/gen_thumb_baked.py

This module itself contains no explicit malware logic (no credential theft, exfiltration, or exploit primitives), but it executes a local command/script located under a user-writable directory (%APPDATA%\npm\higgsfield.cmd) and then downloads remote content to disk based on HTTPS URLs extracted from the command’s untrusted JSON output. The lack of a domain allowlist, signature/content validation, and the “download the last URL” behavior make it a meaningful supply-chain/secondary payload risk if the external tool or its outputs are compromised.

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
Aug 13, 2026, 06:48 AM
Package URL
pkg:socket/skills-sh/crealwork%2Fai-marketing-kit%2Flongform-to-content%2F@7f51b3285235dc00aebdf2b847679311d5b5253e076df69e11699349204c1405
Security Audit — socket — longform-to-content