paper-digest
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalypaper_digest.py
LOWAnomalyLOW
paper_digest.py
The code is not overtly malicious and contains no obfuscation, command execution, persistence, or destructive behavior. It intentionally uploads the selected document and API key to a remote API and trusts a fully configurable base URL. Users should ensure the URL is trusted and HTTPS-only, because an altered URL can capture both the API key and document contents. Remote response size and content are also not constrained before local writes.
Confidence: 97%Severity: 55%
Audit Metadata