image

Warn

Audited by Socket on Sep 10, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
transaction.py

The code appears to be a straightforward local transaction and revision manager, with no evident malicious behavior or supply-chain payload. It performs only expected filesystem persistence and locking. However, caller-controlled transaction IDs create a path traversal and arbitrary-file read/write risk if load(), reserve(), record(), approve(), or reject() are reachable with untrusted input. Validate tx_id against a strict UUID/filename pattern and enforce that resolved paths remain inside TX_DIR. Use safer file creation and permissions for stronger local protection.

Confidence: 98%Severity: 52%
AnomalyLOW
client.py

The code appears to be an image-generation API integration rather than intentionally malicious package code. It does contain meaningful security weaknesses: disabled TLS verification, an internal proxy and fallback credential behavior, unrestricted downloading of response URLs, and insufficient path/size/content validation. These issues can permit credential interception, SSRF, arbitrary file retrieval or resource exhaustion if attacker-controlled URLs or labels are accepted. No direct malware behavior is evident in the supplied fragment, although the missing _cost_track module and truncated ending prevent complete assessment.

Confidence: 94%Severity: 68%
Audit Metadata
Analyzed At
Sep 10, 2026, 10:37 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fimage%2F@31d22207be313cbeef89f3b797e05557ea05dca320599cbcd2a7a6e66639be9c
Security Audit — socket — image