experience-content-media-stock-image-search

Warn

Audited by Socket on Aug 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/download-stock-image.py

This is not obviously malicious malware; it is a utility that retrieves a sensitive Salesforce access token from the local `sf` CLI and uses it to download remote content. The primary security issue is a trust-boundary flaw: the script sends the Bearer access token to a caller-provided HTTPS URL without domain allowlisting or stronger validation, enabling credential leakage if `--url` can be controlled by an attacker. A secondary risk is writing unvalidated remote bytes to disk (and optionally opening certain formats in VS Code), which can be problematic depending on downstream handling. Overall risk is moderate due to credential exposure potential rather than explicit malicious behavior.

Confidence: 70%Severity: 58%
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core purpose and official-tool ecosystem are mostly coherent, but it escalates from search to credentialed local download by reading a raw Salesforce access token and supports automatic billed downloads in non-interactive mode. Data flow appears Salesforce-aligned rather than overtly exfiltrative, so this is not confirmed malware, but it carries medium security risk and disproportionate credential handling for a stock-image helper.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Aug 14, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fexperience-content-media-stock-image-search%2F@eb7b5bacc1ce51132bbe63f1f8a6c6ed8ec36d7c45d25814360360e0feef9153
Security Audit — socket — experience-content-media-stock-image-search