baoyu-imagine

Warn

Audited by Socket on May 21, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/providers/openai.ts

No clear indicators of intentional malware (no obfuscation, no persistence, no dynamic execution, no credential theft beyond using the provided API key for expected API calls). However, this module has moderate security risk due to (1) unvalidated reference image paths leading to arbitrary local file read and upload to a remote endpoint, (2) server-side fetching of img.url without allowlisting (SSRF-like risk), and (3) OPENAI_BASE_URL controlling where the Bearer token is sent. Risk level is therefore highly dependent on trust boundaries for CLI args and environment configuration.

Confidence: 70%Severity: 62%
Audit Metadata
Analyzed At
May 21, 2026, 07:46 AM
Package URL
pkg:socket/skills-sh/yelban%2Fbaoyu-skills.TW%2Fbaoyu-imagine%2F@a8415d3e5f995b65e8657fe2e51c33b841314de0
Security Audit — socket — baoyu-imagine