baoyu-image-gen

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/providers/openrouter.ts

This module appears intended for legitimate image-generation orchestration, not for malware. However, it contains meaningful security risks in common deployment scenarios: it performs unrestricted local file reads based on CLI-provided reference image paths, and it may issue outbound fetch requests to arbitrary http/https URLs found in the OpenRouter response without host allowlisting. If attackers can influence reference image paths or the response contents/URLs, the risk can rise to local file disclosure and SSRF-like network access.

Confidence: 72%Severity: 62%
SecurityMEDIUM
scripts/codex-imagegen/spawn.ts

This module itself does not implement classic JS malware primitives (no eval/Function, no direct network calls, no credential theft logic visible in the snippet). However, it orchestrates execution of an external `codex` CLI with explicitly permissive/unsafe sandbox settings (`--sandbox danger-full-access`) and weakened safety checks (`--skip-git-repo-check`). It passes fully caller-controlled instruction content via stdin and caller-controlled `--image` arguments via the command line, then persists the child’s raw stdout/stderr to disk and parses stdout. In any threat model where `input.instruction` or environment/PATH cannot be strictly trusted, this design creates a high-impact security risk because it enables powerful behavior inside the spawned tool rather than constraining or validating inputs at this layer.

Confidence: 60%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:19 AM
Package URL
pkg:socket/skills-sh/jimliu%2Fbaoyu-skills%2Fbaoyu-image-gen%2F@9393c99094ad10ade49a9e8a17b638fcfc216944ae89a8b5a47c0e1a6526ff02
Security Audit — socket — baoyu-image-gen