etsy-tony-full-gigab2b-assets

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/etsy-tony-full-gigab2b-assets.mjs

The code appears to implement a legitimate GigaB2B product-asset collection workflow and contains no clear malicious payload or intentional data theft. It does present security risks: API-controlled URLs are fetched and written without host, size, or content validation, and raw productId/SKU values can affect filesystem paths. The configurable API base also means credentials could be sent to an unintended endpoint if environment configuration is compromised. These issues should be addressed with strict URL allowlisting, download limits, safe path-component sanitization, and validation of the API base.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 03:46 AM
Package URL
pkg:socket/skills-sh/tony11081%2Fetsy-tony-skills-full%2Fetsy-tony-full-gigab2b-assets%2F@6e219b182f55f4f3ffdabd9eea0171a1cc7f9cd187966b98dc6711309e2e75ea
Security Audit — socket — etsy-tony-full-gigab2b-assets