extract-html

Fail

Audited by Socket on Mar 17, 2026

2 alerts found:

Obfuscated FileAnomaly
Obfuscated FileHIGH
extract_html/vision_client.py

No explicit malicious payloads or backdoors were found in this code fragment. Main security concerns are: (1) The code transmits full image bytes and alt text to external processors (assistant gateway or scillm.acompletion) — risk of leaking sensitive image content depending on api_base trust and deployed environment; (2) It modifies sys.path to import local sibling modules ('scillm' and 'assistant'), creating a supply-chain risk if those modules are untrusted or replaced; (3) There is a functional bug (extract_text_batched returns undefined 'result') that will break batched processing. Recommendations: ensure api_base/api_key target trusted endpoints, avoid sending sensitive images to untrusted services, remove/limit sys.path manipulation or validate imported module locations, and fix the return bug (return 'results').

Confidence: 98%
AnomalyLOW
SKILL.md

SUSPICIOUS: the main extraction purpose is coherent, but the optional Vision/OCR path routes content and credentials to a third-party gateway and the remote-media option ingests arbitrary external content. With missing run.sh/pyproject details and an unverified model reference, this skill has moderate security risk even though it is not confirmed malware.

Confidence: 83%Severity: 64%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fextract-html%2F@72122edb424ca8e69b75673f9791fc2f40b6bc37
Security Audit — socket — extract-html