experience-content-media-stock-image-search

Warn

Audited by Socket on Sep 23, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core purpose and MCP image-search/download capabilities are mostly coherent, and its named external runtimes (`sf`, `python3`) are official. The main concerns are credential forwarding from local Salesforce CLI auth into a repo-local Python script, missing provenance for the `media-management` MCP server, and a non-interactive auto-download path that can spend credits without explicit per-image approval.

Confidence: 85%Severity: 64%
AnomalyLOW
scripts/download-stock-image.py

This is not obviously malicious malware; it is a utility that retrieves a sensitive Salesforce access token from the local `sf` CLI and uses it to download remote content. The primary security issue is a trust-boundary flaw: the script sends the Bearer access token to a caller-provided HTTPS URL without domain allowlisting or stronger validation, enabling credential leakage if `--url` can be controlled by an attacker. A secondary risk is writing unvalidated remote bytes to disk (and optionally opening certain formats in VS Code), which can be problematic depending on downstream handling. Overall risk is moderate due to credential exposure potential rather than explicit malicious behavior.

Confidence: 70%Severity: 58%
Audit Metadata
Analyzed At
Sep 23, 2026, 07:42 AM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fexperience-content-media-stock-image-search%2F@53eaa4844451a1dfad9114123dcbcd4fdfee570cac6e1e3cf9ec9ff0c44eca25
Security Audit — socket — experience-content-media-stock-image-search