3dprint-advisor
Audited by Socket on Mar 14, 2026
2 alerts found:
AnomalySecurityThis is API documentation for Moonraker exposing powerful operations (arbitrary G-code execution, file upload/overwrite/delete, log/config download, host reboot/shutdown). The fragment itself is not malicious code, but the described endpoints present significant security risk if the service is unauthenticated or improperly authorized. Review and enforce strong authentication, least privilege, input validation, and proper file path handling in the implementation before exposing these endpoints to untrusted networks.
SUSPICIOUS. The read/query/profile-generation parts are coherent for a 3D printing advisor, and Moonraker is the correct official API. Risk comes from the expanded footprint: remote config writes, G-code execution, service restarts, and especially SSH/git installation of third-party Klipper extras, which is more powerful than a typical advisory skill and introduces meaningful supply-chain and real-world action risk.