codex-ppt

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior matches the stated PPT-generation purpose, and required credentials are mostly proportionate. The main risk is data-flow integrity: the fallback path can route prompts and API keys to arbitrary OpenAI-compatible base URLs through custom local scripts, so users could unknowingly send content and credentials to third-party intermediaries. Supply-chain risk is moderate because execution depends on repo-provided bootstrap/runtime scripts from a personal GitHub publisher, but there is no clear evidence of malicious intent.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 02:27 AM
Package URL
pkg:socket/skills-sh/ningzimu%2Fcodex-ppt-skill%2Fcodex-ppt%2F@5aefd8916efe3bad5d0c616473187f94836af630