image-forge
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyscripts/image_pipeline.py
LOWAnomalyLOW
scripts/image_pipeline.py
The fragment is a readable ImageMagick command builder and executor, not apparent malware. It avoids direct shell injection by using a subprocess argument list, but untrusted specifications can control filesystem paths and arbitrary ImageMagick options through the raw operation. Use only with trusted specifications or enforce path allowlists, disable risky ImageMagick delegates/protocols, restrict raw arguments, and apply resource limits and ImageMagick security policy.
Confidence: 97%Severity: 62%
Audit Metadata