generative-media
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
AnomalyAnomalyevals/files/restage_product.py
LOWAnomalyLOW
evals/files/restage_product.py
The code appears to be a legitimate product-image processing utility, not intentionally malicious. The principal security issue is shell command injection through the unquoted photo-derived output path, along with the risk of executing an unpinned npm tool via npx. Product images and masks are transmitted to OpenAI, which should be treated as an intentional privacy/data-sharing consideration. The shown fragment is also syntactically incomplete.
Confidence: 98%Severity: 62%
Audit Metadata