hellomedia

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/generate.py

No direct evidence of intentional malware (e.g., backdoor, obfuscated payload execution, reverse shell, or credential theft) appears in this fragment. The dominant security concerns are (1) SSRF-like risk via direct downloading of http/https URLs found in provider response payloads without an allowlist in this code, and (2) local file exfiltration risk by design through uploading/embedding arbitrary --image paths to external providers. Additionally, dependency/supply-chain risk is non-trivial due to reliance on dynamically imported _auth_discovery/_common helpers that could influence network/proxy/auth and downloading behavior. Treat this module as a network-capable data processor with moderate security risk rather than clear malware.

Confidence: 62%Severity: 56%
Audit Metadata
Analyzed At
Jul 25, 2026, 12:07 PM
Package URL
pkg:socket/skills-sh/hellowind777%2Fhello-multimodal%2Fhellomedia%2F@20ba9a243259c1b85e04b7877b5454d19de79a5f
Security Audit — socket — hellomedia