plantuml
Warn
Audited by Socket on Oct 10, 2026
1 alert found:
AnomalyAnomalyscripts/extract_and_convert_puml.py
LOWAnomalyLOW
scripts/extract_and_convert_puml.py
This module itself does not show overt malware behavior (no exfiltration, reverse shells, or credential theft), and the subprocess call is not shell-based. However, it materially increases risk because it executes a local Java JAR (selected via PLANTUML_JAR or local filesystem) and passes attacker-influenced PlantUML text from an untrusted Markdown file into that renderer. Additionally, --output-dir is not sanitized, allowing unintended filesystem write locations for generated outputs and the temporary .puml file. Overall: low likelihood of malicious intent in this specific code, but moderate operational/supply-chain risk if inputs or the runtime environment are not trusted.
Confidence: 62%Severity: 52%
Audit Metadata