flask-app-builder

Warn

Audited by Socket on Jun 23, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
references/app-registry.md
AnomalyLOW
references/feature-patterns.md

No strong, direct malware indicators (no eval/Function/command execution/backdoor persistence observed). The main supply-chain/security concerns are (1) sensitive credential-dependent external calls: runtime key retrieval from a third-party endpoint and (2) forwarding of arbitrary task_text to an external bridge service using a server secret token, which could enable data exfiltration depending on how task_text is sourced. Additional issues include leaking raw exception messages to clients and disclosing saved upload paths. Recommend auditing call sites for get_api_key_from_kys() and post_to_ecdash(), enforcing content/size limits on uploads, and suppressing detailed exception strings.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Jun 23, 2026, 06:14 AM
Package URL
pkg:socket/skills-sh/Liberty-Emporium%2Fecho-v1%2Fflask-app-builder%2F@9ad9841e03aa4ad2e8db8aac3d8e7c97acd0278cc6469dae24e2f30a4a3b587d
Security Audit — socket — flask-app-builder