powerpoint

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/Invoke-PptxPipeline.ps1

This PowerShell module is primarily a benign orchestrator that sets up a Python environment (via uv) and runs multiple helper scripts to export and validate PPTX content, including optional vision validation when prompts are supplied. It contains no explicit malicious logic in the fragment (no secrets, obfuscation, or direct exfiltration). The key security concerns are indirect and supply-chain related: automatic dependency installation (uv sync) and the delegated network-capable behavior potential inside validate_slides.py/SDK. Additionally, it can delete slide-*.jpg files within a user-provided ImageOutputDir, which could cause data loss if misused. Review the invoked Python scripts and dependency/lockfiles to make a definitive malware determination.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 10:50 AM
Package URL
pkg:socket/skills-sh/microsoft%2Fhve-core%2Fpowerpoint%2F@47171bf7518bf3769772b03655e66b59d611a64c