minimax-pdf

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/render_body.py

This module is a PDF rendering utility with significant security-relevant behaviors: it can execute code from newly installed dependencies at runtime via unpinned pip installation (with '--break-system-packages'), and it allows untrusted JSON to reference arbitrary local font and image file paths that may be embedded into the generated PDF. The math/chart/flowchart rendering pipeline further increases the risk of denial-of-service through compute-intensive rendering driven by attacker-controlled data. No clear evidence of overt malware (exfiltration/backdoor/reverse shell) is present in the snippet, but supply-chain and local file inclusion/confidentiality risks are meaningful.

Confidence: 62%Severity: 67%
Audit Metadata
Analyzed At
Sep 15, 2026, 05:59 AM
Package URL
pkg:socket/skills-sh/minimax-ai%2Fskills%2Fminimax-pdf%2F@f50367b5788b23f1b506cab512df5cc0936031d1c7408e47fdf88325647e3e6d
Security Audit — socket — minimax-pdf