image-forge

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/image_pipeline.py

The fragment is a readable ImageMagick command builder and executor, not apparent malware. It avoids direct shell injection by using a subprocess argument list, but untrusted specifications can control filesystem paths and arbitrary ImageMagick options through the raw operation. Use only with trusted specifications or enforce path allowlists, disable risky ImageMagick delegates/protocols, restrict raw arguments, and apply resource limits and ImageMagick security policy.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 05:08 AM
Package URL
pkg:socket/skills-sh/tdimino%2Fclaude-code-minoan%2Fimage-forge%2F@7aa76a2c94d6c782cd069a50a1c229cb2d2ea9be1324bfb0518bb3de2ab79fbe
Security Audit — socket — image-forge