generative-media

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Anomaly
AnomalyLOW
evals/files/restage_product.py

The code appears to be a legitimate product-image processing utility, not intentionally malicious. The principal security issue is shell command injection through the unquoted photo-derived output path, along with the risk of executing an unpinned npm tool via npx. Product images and masks are transmitted to OpenAI, which should be treated as an intentional privacy/data-sharing consideration. The shown fragment is also syntactically incomplete.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 12, 2026, 12:12 PM
Package URL
pkg:socket/skills-sh/lynricsy%2Fhyperskills%2Fgenerative-media%2F@76c279dd5c28086da7c1cea74ae9e287cf18297cf2759068e4ebc6d0138da433
Security Audit — socket — generative-media