chanjing-customised-person

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/upload_file.py

Best-fitting report is the one that emphasizes supply-chain/import hijack (sys.path + _auth) and the upload-as-exfiltration risk inherent to uploading the full local file to a server-provided sign_url. This module itself does not show explicit malware (no backdoor/exec/persistence), but it does perform high-impact data transfer (file bytes) to an unvalidated, server-provided upload URL and it alters import resolution order, which can enable malicious local module replacement. Review/mitigate by removing sys.path injection, validating sign_url destination, and hardening/inspecting _auth.py and environment control.

Confidence: 66%Severity: 56%
Audit Metadata
Analyzed At
Mar 27, 2026, 07:38 PM
Package URL
pkg:socket/skills-sh/chanjing-ai%2Fchan-skills%2Fchanjing-customised-person%2F@7ed9cd44f3600ac4dda0566b7dc96f74757abd5b