open-ppt

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/local-export/export-pptd.mjs

The fragment appears to be a legitimate PPTD-to-PPTX offline exporter. It does not provide clear evidence of malware or intentional sabotage. It has security weaknesses when processing untrusted projects: arbitrary outbound image fetching, insufficiently constrained local image paths, and unbounded data/WASM processing. These should be mitigated with URL allowlisting or network isolation, strict resolved-path containment, size/time limits, and trusted WASM verification.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 10, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/lora-sys%2Fskills%2Fopen-ppt%2F@f05153963525038cb33e267e7211e777f75b1c0ebd6e11f79bcbd7e00a0c8e7d
Security Audit — socket — open-ppt