baoyu-imagine

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/providers/openai.ts

No clear indicators of intentional malware (no obfuscation, no persistence, no dynamic execution, no credential theft beyond using the provided API key for expected API calls). However, this module has moderate security risk due to (1) unvalidated reference image paths leading to arbitrary local file read and upload to a remote endpoint, (2) server-side fetching of img.url without allowlisting (SSRF-like risk), and (3) OPENAI_BASE_URL controlling where the Bearer token is sent. Risk level is therefore highly dependent on trust boundaries for CLI args and environment configuration.

Confidence: 70%Severity: 62%
Audit Metadata
Analyzed At
Apr 26, 2026, 03:59 AM
Package URL
pkg:socket/skills-sh/JimLiu%2Fbaoyu-skills%2Fbaoyu-imagine%2F@eddb4a9a7be1c03c3881fc7ac0bc8143ca3af8d0