ai-seo-articles

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/process-inline-images.mjs

No clear malicious backdoor or direct malware behavior is evident in this module (no dynamic code execution, no shell/process spawning, no intentional system-data theft). However, the script contains a high-severity supply-chain credential exposure: a hardcoded bearer token used for remote MCP/CMS API calls. It also performs automated network interactions and writes back to an on-disk draft based on untrusted content. These factors make the module risky if shipped publicly or used in untrusted pipelines, even if the intent is primarily image generation/upload automation.

Confidence: 78%Severity: 82%
Audit Metadata
Analyzed At
Apr 17, 2026, 09:14 AM
Package URL
pkg:socket/skills-sh/blink-new%2Fclaude%2Fai-seo-articles%2F@2e7ea7519d0e8ad1a0e24fca0fb00c6422f9158e