lov-any2pdf

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/md2pdf.py

No strong evidence of classic malware/backdoors in this fragment (no eval/exec/subprocess/credential theft/persistence). The primary security concern is build-time danger from untrusted Markdown: it can trigger outbound HTTP(S) requests to arbitrary user-supplied image URLs and read/embed local files via file:// or relative paths if they exist, caching downloaded content into system temp directories. This materially increases the risk profile in supply-chain or CI contexts where the generator processes untrusted documents; network egress restrictions and image source allowlists/disablement are recommended.

Confidence: 66%Severity: 60%
Audit Metadata
Analyzed At
Aug 11, 2026, 12:19 PM
Package URL
pkg:socket/skills-sh/lovstudio%2Fany2pdf%2Flov-any2pdf%2F@43a4ba6e214c983f5b9cc095356023cfa56d2b14f6a390e938a9792208977a5c
Security Audit — socket — lov-any2pdf