ecommerce-geekbi-temu-search-by-image

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/geekbi_temu_goods_image_search.py

The code appears to be an API integration and local response-caching utility rather than malware. It intentionally sends the configured API key and search parameters to the NexScope endpoint and stores returned data locally. The unsanitized SESSION_ID creates a filesystem path traversal/absolute-path write risk for callers able to control environment variables. NEXSCOPE_PROXY_BASE can redirect credentials and data to an unintended endpoint if the environment is compromised. The supplied fragment is also syntactically incomplete because CONTRACT_JSON has no assigned value and the final main call is unfinished.

Confidence: 98%Severity: 56%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:13 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fecommerce-geekbi-temu-search-by-image%2F@846a5ac68622693a983c0ef3fc002c3e96dde3493c376d7c4a54bc173da1d58d
Security Audit — socket — ecommerce-geekbi-temu-search-by-image