3dprint-advisor

Warn

Audited by Socket on Mar 14, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
references/moonraker_api.md

This is API documentation for Moonraker exposing powerful operations (arbitrary G-code execution, file upload/overwrite/delete, log/config download, host reboot/shutdown). The fragment itself is not malicious code, but the described endpoints present significant security risk if the service is unauthenticated or improperly authorized. Review and enforce strong authentication, least privilege, input validation, and proper file path handling in the implementation before exposing these endpoints to untrusted networks.

Confidence: 90%Severity: 60%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The read/query/profile-generation parts are coherent for a 3D printing advisor, and Moonraker is the correct official API. Risk comes from the expanded footprint: remote config writes, G-code execution, service restarts, and especially SSH/git installation of third-party Klipper extras, which is more powerful than a typical advisory skill and introduces meaningful supply-chain and real-world action risk.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:34 PM
Package URL
pkg:socket/skills-sh/santiagomoneta%2F3DPrintAdvisor%2F3dprint-advisor%2F@2a78ff260a89ffc32445dc0378fd751c969edc45