sci-figure

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
sci_figure/image_processor.py

The code is a local image-saving utility with no evident malicious behavior. It has a moderate path traversal and arbitrary-file-overwrite risk because output filenames and the format extension are not sanitized before being passed to Image.save. Restrict fmt to an allowlist, reject absolute paths and separators in name/sublabel, resolve the final path, and verify it remains under output_dir. The displayed fragment also appears incomplete because it ends with 'return filepat'.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 06:20 PM
Package URL
pkg:socket/skills-sh/shzhao27208%2Faut_sci_write%2Fsci-figure%2F@ac158ac3a5186b0ca9f2a5c0506f4092cc9361282c98f79719d114aa10b7e9ad
Security Audit — socket — sci-figure