baoyu-image-gen
Audited by Socket on Sep 15, 2026
2 alerts found:
AnomalySecurityThis module appears intended for legitimate image-generation orchestration, not for malware. However, it contains meaningful security risks in common deployment scenarios: it performs unrestricted local file reads based on CLI-provided reference image paths, and it may issue outbound fetch requests to arbitrary http/https URLs found in the OpenRouter response without host allowlisting. If attackers can influence reference image paths or the response contents/URLs, the risk can rise to local file disclosure and SSRF-like network access.
This module itself does not implement classic JS malware primitives (no eval/Function, no direct network calls, no credential theft logic visible in the snippet). However, it orchestrates execution of an external `codex` CLI with explicitly permissive/unsafe sandbox settings (`--sandbox danger-full-access`) and weakened safety checks (`--skip-git-repo-check`). It passes fully caller-controlled instruction content via stdin and caller-controlled `--image` arguments via the command line, then persists the child’s raw stdout/stderr to disk and parses stdout. In any threat model where `input.instruction` or environment/PATH cannot be strictly trusted, this design creates a high-impact security risk because it enables powerful behavior inside the spawned tool rather than constraining or validating inputs at this layer.