baoyu-image-gen

Warn

Audited by Socket on Jun 26, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/providers/openai.ts

No clear indicators of intentional malware (no obfuscation, no persistence, no dynamic execution, no credential theft beyond using the provided API key for expected API calls). However, this module has moderate security risk due to (1) unvalidated reference image paths leading to arbitrary local file read and upload to a remote endpoint, (2) server-side fetching of img.url without allowlisting (SSRF-like risk), and (3) OPENAI_BASE_URL controlling where the Bearer token is sent. Risk level is therefore highly dependent on trust boundaries for CLI args and environment configuration.

Confidence: 70%Severity: 62%
SecurityMEDIUM
scripts/codex-imagegen/spawn.ts
Audit Metadata
Analyzed At
Jun 26, 2026, 08:19 AM
Package URL
pkg:socket/skills-sh/guanyang%2Fopen-agent-hub%2Fbaoyu-image-gen%2F@349dec081be100ed8e4a7d6445480ff6ac74d6eb9c7189c6c37387bde8c375f7
Security Audit — socket — baoyu-image-gen