springboot-microservice-gen

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/springboot-microservice-gen.py

No direct malicious behavior (e.g., backdoor, data theft) is evident in this Python module. However, it performs security-sensitive operations: it downloads zip archives from the network and extracts them with ZipFile.extractall without validating archive member paths (zip-slip risk), and it executes the extracted Spring CLI binary without integrity/signature verification. This creates a plausible supply-chain/host compromise risk if the zip is tampered or malicious.

Confidence: 62%Severity: 63%
Audit Metadata
Analyzed At
Aug 7, 2026, 08:53 AM
Package URL
pkg:socket/skills-sh/superproxy%2Fspringboot-microservice-gen-skills%2Fspringboot-microservice-gen%2F@a245a86665c60a2864bf11c8ad624c1a52685dd2ae14e0dceb156f7c46326d23
Security Audit — socket — springboot-microservice-gen