ecommerce-reverse-product-image-search-api

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/nexscope_paths.py

No clear malware or covert data-theft behavior is present. The code contains legitimate but security-sensitive file upload and download functionality. Main risks are unsanitized SESSION_ID path construction, arbitrary outbound HTTP(S) access through download_media(), unlimited download size, and transmission of an environment-provided API key to the configured endpoint. The fragment is syntactically incomplete as provided.

Confidence: 97%Severity: 70%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:15 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fecommerce-reverse-product-image-search-api%2F@252e5c7a220225c4960a6fe538325ae01d08420085dada45e33321b2d1891f7c
Security Audit — socket — ecommerce-reverse-product-image-search-api