epub
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
AnomalyAnomalyscripts/epub-extract-knowledge
LOWAnomalyLOW
scripts/epub-extract-knowledge
No clear evidence of intentional malware is present in the provided code fragment. However, the LLM-backed mode creates a significant security/privacy risk: the tool sends extracted EPUB text to an externally specified HTTP endpoint and transmits an API key via an Authorization Bearer header. This is a supply-chain/integration data-exfiltration concern rather than classic malware. Confidence is reduced because the snippet appears incomplete/corrupted (missing default_prompt value and an invalid main() invocation), limiting certainty about full runtime behavior.
Confidence: 46%Severity: 58%
Audit Metadata