ecommerce-mercado-market-intelligence

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/damai_mercado_market_intelligence.py

The code is primarily an API client with caching and workspace persistence. It contains no clear malware or obfuscated payload. The main security issue is unsanitized SESSION_ID path construction, which can redirect metadata and response writes outside the intended workspace under attacker-controlled environment conditions. A secondary risk is that NEXSCOPE_PROXY_BASE can redirect authenticated requests and expose the API key if misconfigured or attacker-controlled. The fragment is also syntactically incomplete as provided.

Confidence: 97%Severity: 55%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:15 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fecommerce-mercado-market-intelligence%2F@127c10d60373fa0ce207ceb31eef0d4d28dec9871db38aaf9de79dbe89fab328
Security Audit — socket — ecommerce-mercado-market-intelligence