lov-sync-with-synology

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/fake_dsm_server.py

The code appears to be a fake DSM test server rather than malware. It contains a significant path traversal risk in both filesystem reads and uploads because requested paths are not normalized and checked to remain beneath the configured root. Authentication is intentionally weak and several endpoints are unauthenticated, which is acceptable only for an isolated test fixture. The hardcoded SID and token are placeholders, not evidence of credential theft. The literal fragment also appears syntactically incomplete at the final SystemExit call.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 10, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/lovstudio%2Fskills%2Flov-sync-with-synology%2F@080bb1f8cae411b982196f2fbb786b281b0cb0eb0da1279a357881c00fa5bcc4
Security Audit — socket — lov-sync-with-synology