ecommerce-geekbi-temu-market-research

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/geekbi_temu_keyword_search.py

The code appears to be a legitimate API integration and local response-caching utility, with no clear malware behavior. The primary security concerns are unvalidated SESSION_ID path construction, which may permit filesystem path escape, and the ability to redirect API credentials and request data to an arbitrary endpoint through NEXSCOPE_PROXY_BASE. The supplied fragment is also syntactically incomplete and would not run without correction.

Confidence: 98%Severity: 56%
AnomalyLOW
scripts/geekbi_temu_category_list.py

The code appears intended to be an API client with local caching and session-based response storage, not malware. It does intentionally transmit NEXSCOPE_API_KEY and request metadata to the configured API base, so an attacker-controlled NEXSCOPE_PROXY_BASE could harvest the credential. SESSION_ID also permits filesystem path traversal if externally controlled. The provided fragment is incomplete and nonfunctional as written because CONTRACT_JSON and the final main invocation are malformed. No clear malicious payload, obfuscation, reverse shell, persistence, or destructive behavior is present.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:13 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fecommerce-geekbi-temu-market-research%2F@4fc60fa2951d894373494dc531fb5127514a5d3b8651f571adbb92a717a0388c
Security Audit — socket — ecommerce-geekbi-temu-market-research