ecommerce-amazon-search

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/amazon_search.py

No clear malware or intentional data theft is present. The code is a straightforward API client with caching and response persistence, but it has security weaknesses: an arbitrary environment-configured endpoint receives the API key, HTTP is not restricted to TLS, SESSION_ID permits path traversal or absolute-path output redirection, and API responses are stored without protection or size limits. The fragment is syntactically incomplete as provided.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:14 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fecommerce-amazon-search%2F@ca749985016c59719be04fdd8deefa4988824b3e6633ab5284daf7d374dadf82
Security Audit — socket — ecommerce-amazon-search