hwpx

Warn

Audited by Socket on Aug 30, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/office/unpack.py

No direct evidence of intentional malware (exfiltration, backdoor, or command execution) is present in this code fragment. However, it is security-sensitive for untrusted archives: it can be vulnerable to Zip Slip/path traversal because ZIP entry names are used directly to construct destination paths, enabling writes outside the chosen output directory. It also lacks resource limits (DoS via zip bombs/large entries) and does not show explicit hardening for lxml XML parsing of attacker-controlled content.

Confidence: 74%Severity: 78%
Audit Metadata
Analyzed At
Aug 30, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/jkf87%2Fhwpx-skill%2Fhwpx%2F@96a2633f23a08f707679d7e212ebdc59948260e6
Security Audit — socket — hwpx