@1892/agent-blog
Audited by Socket on Sep 12, 2026
2 alerts found:
SecurityAnomalyThe code is an HTML-to-Markdown importer, not clear malware. Its main security concern is unsafe trust-boundary handling: arbitrary fetched HTML, especially inline JavaScript, is embedded into generated posts without sanitization, creating a likely stored-XSS or script-execution risk when posts are rendered. The user-controlled URL also introduces SSRF risk depending on the HTTP client's protections, and the unvalidated date and unescaped YAML fields create additional robustness and injection concerns. The pasted fragment has syntax errors and would need correction before execution.
No direct malware behavior (no networking/subprocess/credential theft) is evident in this image-generation module. The primary security concern is dynamic execution of a local configuration module via exec_module at import time, which becomes arbitrary code execution if config.py/config.example.py can be modified by an attacker. A secondary concern is unrestricted out_path usage for directory creation and file writes, which can enable unintended filesystem writes in the hosting application’s permissions if out_path is not trusted.