llamaparse
Fail
Audited by Socket on Mar 20, 2026
1 alert found:
Obfuscated FileObfuscated Filescripts/example.ts
HIGHObfuscated FileHIGH
scripts/example.ts
The code is a legitimate-looking client for uploading and parsing local files with LlamaCloud, but it carries moderate security risk due to its ability to upload arbitrary local files (potential data exfiltration), reuse of the API key in Authorization headers for presigned URL downloads, and writing remote filenames to disk without sanitization. There are no clear signs of intentional malware or backdoors. Treat usage as potentially dangerous in environments containing sensitive data and apply mitigations (restrict API key, sanitize filenames, avoid parsing secrets).
Confidence: 98%
Audit Metadata