biostudies-arrayexpress-skill

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/rest_request.py

The code is a legitimate generic HTTP fetching and response summarization utility, with no clear evidence of intentional malware or obfuscation. However, its unrestricted user-controlled URL, absolute-URL bypass, forwarded headers, and unrestricted raw output path create significant security risks in an exposed service. Restrict schemes and destinations, block private/link-local networks as appropriate, validate redirects, filter sensitive headers, and constrain raw_output_path to a safe directory.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 20, 2026, 12:21 PM
Package URL
pkg:socket/skills-sh/openai%2Fplugins%2Fbiostudies-arrayexpress-skill%2F@6d74309784aff00b8884ce20e05eda1b861f6f2e8283824212da03a7d7490408
Security Audit — socket — biostudies-arrayexpress-skill