awesome-webpage-image-download

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/image_download.py

This module is best characterized as an attacker-influenceable ‘image URL downloader’ that reads URLs from untrusted stdin and fetches them over the network without allowlists/egress controls, creating an SSRF risk depending on runtime network privileges. It also writes attacker-controlled remote bytes to disk (subject to heuristic image signature/content-type checks and sanitized filenames). While there is no clear evidence of intentional malware (no exec/persistence/secret theft in this code), its network-and-write capabilities make it security-sensitive in a supply-chain or pipeline context.

Confidence: 74%Severity: 62%
Audit Metadata
Analyzed At
Aug 1, 2026, 09:27 AM
Package URL
pkg:socket/skills-sh/opensquilla%2Fopensquilla%2Fawesome-webpage-image-download%2F@d5cf1852e9b4b6341123f7f56ea9b56d16dc146a18246249cb39279fa656200c
Security Audit — socket — awesome-webpage-image-download