byted-seedream-image-generate

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/seedream_image_generate.py

This module appears to be a legitimate API client for image generation, not an obvious malware/backdoor implementation. However, it has a serious security weakness: it logs the full Authorization header (Bearer API key) and detailed request payloads to stdout, which can leak credentials and user data into CI logs, terminals, or monitoring systems. Additionally, API_BASE is environment-controlled without allowlist/validation, so a poisoned environment could redirect the bearer token and prompts to an unintended endpoint. Remediate by removing/redacting secret logging, using a configurable debug logger, and validating/allowlisting API destinations.

Confidence: 73%Severity: 78%
Audit Metadata
Analyzed At
Aug 19, 2026, 05:32 PM
Package URL
pkg:socket/skills-sh/hk-hub%2Fagentskills%2Fbyted-seedream-image-generate%2F@7013dd9daa07f1cc734df88534079da47a78b5303555e1e1a4808e156c0d0e5f
Security Audit — socket — byted-seedream-image-generate