create-svg

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
src/create_svg/io.py

The code appears to be a conventional YAML/resource loader and contains no evident malware. The primary security concern is path traversal or arbitrary file disclosure when theme references, base directories, scene paths, or template names are influenced by untrusted input. Restrict paths to approved project directories and validate names as safe relative filenames before use. `yaml.safe_load()` reduces deserialization risk. The shown fragment also appears incomplete at the final function expression.

Confidence: 97%Severity: 57%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fcreate-svg%2F@2512277915033402e047704b3e88ba4404b8bc08d516b8403d063f2240c29db5
Security Audit — socket — create-svg