Skywork-ppt

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/upload_files.py

Overall this module behaves like a legitimate batch file uploader, but it has strong data egress potential: it uploads arbitrary local files provided by the user to a configurable remote `/upload_oss` endpoint authenticated with a Bearer API key. The main security concern is contextual trust—if the configured destination or API key source is tampered with, sensitive local files could be exfiltrated. No clear malware behavior (backdoor, exec, persistence, or stealth) is present in the shown code. The multipart builder contains unusual logic that may cause request-formatting bugs, increasing the need for functional testing rather than indicating intentional concealment.

Confidence: 66%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/skyworkai%2Fskywork-skills%2Fskywork-ppt%2F@7fb9e9f6c7d65072f35bdf121b9e60af69101fe6