1688-product-search

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/image_search_handler.py

This module primarily implements a legitimate “upload image then search” workflow against a fixed 1688/OpenAPI endpoint, with credentials loaded from environment variables and signed requests. The key security issues are misuse/exposure vectors: it fetches attacker-supplied URLs without allowlisting (SSRF risk) and it can read arbitrary local files from paths provided via image_source (potential local file data exfiltration to the remote API if an attacker can control inputs). Additionally, sys.path manipulation increases import-resolution/supply-chain risk. No strong indicators of intentional malware/backdoor are visible in the provided fragment.

Confidence: 66%Severity: 66%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:18 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2F1688-product-search%2F@2d35b825685642e754b60f2f0dfc8428101430e3