DICOM Processing

Warn

Audited by Socket on Feb 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Installation of third-party script detected Overall, the fragment is benign and suitable for its intended purpose of teaching DICOM processing with pydicom/DCMTK. To elevate security hygiene, incorporate explicit de-identification guidance, ensure metadata handling is auditable, and recommend safe defaults for bulk operations (e.g., stop_before_pixels, access controls). No malicious behavior detected; low to moderate security risk due to PHI handling and potential de-identification gaps. LLM verification: This SKILL.md is coherent and its capabilities align with its stated purpose (DICOM processing). There is no evidence of intentionally malicious code. However, there are supply-chain and operational risks: unpinned pip dependencies (multiple occurrences) increase the chance of pulling malicious packages; example commands demonstrate sending DICOM data (PHI) to arbitrary hosts via DCMTK without guidance on secure transport or de-identification; and documentation omits warnings about authenticatio

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 24, 2026, 03:55 AM
Package URL
pkg:socket/skills-sh/aurabx%2Fskills%2Fdicom-processing%2F@4f78781ad6810150de0a89f8f286e4d9bfefb048