filtmall-shopping

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
assets/filtalgo-cli.cjs

The snippet contains two major security concerns: (1) potential command injection via child_process.exec in openBrowser(urlStr), where urlStr can come from remote auth responses and is interpolated into a shell command without robust escaping; and (2) disabled TLS certificate validation (rejectUnauthorized:false) for outbound HTTPS requests, enabling MITM attacks that could tamper with verification URLs and other responses. These issues together significantly increase the risk of remote compromise or token/session misuse if an attacker can influence traffic or responses.

Confidence: 78%Severity: 88%
Audit Metadata
Analyzed At
Sep 2, 2026, 02:25 AM
Package URL
pkg:socket/skills-sh/filtalgo%2Ffiltmall-shopping-skill%2Ffiltmall-shopping%2F@94abd95512ca8089d473c3cf0d7b397f9b4913e9
Security Audit — socket — filtmall-shopping