open-ppt
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
AnomalyAnomalyscripts/local-export/export-pptd.mjs
LOWAnomalyLOW
scripts/local-export/export-pptd.mjs
The fragment appears to be a legitimate PPTD-to-PPTX offline exporter. It does not provide clear evidence of malware or intentional sabotage. It has security weaknesses when processing untrusted projects: arbitrary outbound image fetching, insufficiently constrained local image paths, and unbounded data/WASM processing. These should be mitigated with URL allowlisting or network isolation, strict resolved-path containment, size/time limits, and trusted WASM verification.
Confidence: 96%Severity: 62%
Audit Metadata