chat-with-arxiv
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
AnomalyAnomalyexamples/paper_content_processor.py
LOWAnomalyLOW
examples/paper_content_processor.py
The code appears to be a legitimate PDF ingestion and text-processing utility and contains no clear malware indicators. Security concerns are an unrestricted caller-controlled outbound URL, lack of response and PDF resource limits, unbounded cache growth, and missing chunk parameter validation. The URL handling should restrict schemes and destinations or use an allowlist, and resource and parameter limits should be enforced.
Confidence: 98%Severity: 58%
Audit Metadata