seo-image-gen

Warn

Audited by Socket on Jun 16, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md
AnomalyLOW
references/seo-image-presets.md

This fragment is not malicious code itself; it is preset configuration/documentation. The main security concern is that presets include ImageMagick `post_processing` strings (including shell-like chaining with `&&`). If the consuming application executes these `post_processing` strings via a shell or without strict allowlisting/sanitization—especially when loading user-created presets from `~/.banana/presets/`—it can become a command-execution / command-injection vector. Review the downstream preset loader/executor to confirm it does not interpret `post_processing` as a shell command string and that it validates/allowlists operations and paths.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/Infrasity-Labs%2Fdev-gtm-claude-skills%2Fseo-image-gen%2F@56ab7d70629b83102db7f51dde24d56ca340b784802fdbe67454a3fccb31a172
Security Audit — socket — seo-image-gen