image
Audited by Socket on Sep 10, 2026
2 alerts found:
Anomalyx2The code appears to be a straightforward local transaction and revision manager, with no evident malicious behavior or supply-chain payload. It performs only expected filesystem persistence and locking. However, caller-controlled transaction IDs create a path traversal and arbitrary-file read/write risk if load(), reserve(), record(), approve(), or reject() are reachable with untrusted input. Validate tx_id against a strict UUID/filename pattern and enforce that resolved paths remain inside TX_DIR. Use safer file creation and permissions for stronger local protection.
The code appears to be an image-generation API integration rather than intentionally malicious package code. It does contain meaningful security weaknesses: disabled TLS verification, an internal proxy and fallback credential behavior, unrestricted downloading of response URLs, and insufficient path/size/content validation. These issues can permit credential interception, SSRF, arbitrary file retrieval or resource exhaustion if attacker-controlled URLs or labels are accepted. No direct malware behavior is evident in the supplied fragment, although the missing _cost_track module and truncated ending prevent complete assessment.