plantuml

Warn

Audited by Socket on Oct 10, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/extract_and_convert_puml.py

This module itself does not show overt malware behavior (no exfiltration, reverse shells, or credential theft), and the subprocess call is not shell-based. However, it materially increases risk because it executes a local Java JAR (selected via PLANTUML_JAR or local filesystem) and passes attacker-influenced PlantUML text from an untrusted Markdown file into that renderer. Additionally, --output-dir is not sanitized, allowing unintended filesystem write locations for generated outputs and the temporary .puml file. Overall: low likelihood of malicious intent in this specific code, but moderate operational/supply-chain risk if inputs or the runtime environment are not trusted.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Oct 10, 2026, 12:30 AM
Package URL
pkg:socket/skills-sh/spillwavesolutions%2Fagent_rulez%2Fplantuml%2F@0b9bf102b5a646c2c624fa30c3b0dfefc6db3ebfd3617e708d0509897c66d575