azure-image-gen

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/generate.py

No strong evidence of intentional malware (no backdoor, persistence, command execution, or data exfiltration beyond a configurable Azure API call) is present in this fragment. The primary security concern is that the generated index.html embeds the (user- and/or API-influenced) prompt text without HTML escaping, enabling HTML/JavaScript injection when the gallery is opened. Additional lower-severity risks include loading secrets from a relative .env file and writing files to a user-controlled output directory. Treat as a moderate security-risk utility rather than a malware package, with reduced confidence due to apparent syntax/integrity issues in the provided code.

Confidence: 54%Severity: 55%
Audit Metadata
Analyzed At
Mar 31, 2026, 12:05 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fazure-image-gen%2F@6deb471219c2bc0717cb0a58667af3b8718f3e1a