retail-virtual-tryon

Warn

Audited by Socket on Sep 21, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
scripts/server.py

The code appears to implement legitimate virtual try-on functionality and contains no clear malware or intentional sabotage. However, it exposes powerful unauthenticated file and cloud-object access primitives: arbitrary gs:// reads, broad local path handling, arbitrary catalog scanning, and publicly mounted cache content. Wildcard CORS with credentials and missing request-size limits further increase exposure. Restrict paths and buckets, add authentication and authorization, sanitize filenames, validate media and request sizes, avoid exposing .catalog_cache, and return generic error messages.

Confidence: 97%Severity: 78%
AnomalyLOW
assets/export-template/deploy_cloudrun.sh

The code is a straightforward Google Cloud Run deployment script with no evident malware or supply-chain backdoor. It performs privileged cloud changes and uploads the entire current directory. The explicit `--allow-unauthenticated` flag creates a significant exposure risk if public access is not intended, and the source directory should be checked for secrets before deployment.

Confidence: 98%Severity: 52%
Audit Metadata
Analyzed At
Sep 21, 2026, 05:52 AM
Package URL
pkg:socket/skills-sh/google%2Fadk-recipes%2Fretail-virtual-tryon%2F@133bb3e0749393e4a4ec644462d4c839510e8439d4764fcb0bd83ae7f29da777
Security Audit — socket — retail-virtual-tryon