brand-illustrate

Warn

Audited by Socket on Aug 10, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/illustrate.py

No strong evidence of built-in stealth malware (no exfiltration, credential theft, or obfuscated payloads) in this module. The primary security risk is supply-chain/orchestration: it dynamically discovers and executes external backend scripts/executables based on environment variables and configurable directory roots, creating a serious arbitrary code execution boundary if those locations are attacker-influenced. Separately, it generates gallery.html with unescaped untrusted values (caption/sub/src/attributes), creating a plausible HTML injection/XSS risk when opening the generated gallery if an attacker can control files/metadata under the scanned directory.

Confidence: 68%Severity: 65%
Audit Metadata
Analyzed At
Aug 10, 2026, 09:34 PM
Package URL
pkg:socket/skills-sh/glebis%2Fhumane-agentic-design%2Fbrand-illustrate%2F@330a43b117efec00c1e809aea044c7fc6f6a018b650ac34db6c460b6c48a3386
Security Audit — socket — brand-illustrate