sn-ppt-standard

Warn

Audited by Socket on Sep 21, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/launch_workbench.py

No clear malware or sabotage is present in this fragment. The code primarily launches a local workbench and integrates with configured gateways. Security warnings apply because it reads sensitive API keys, sends them to a configured endpoint, passes them in subprocess arguments, executes environment-selected Node/npm code, and may bind the service to all interfaces in container environments. The gateway URL and launcher path should be trusted and credentials should preferably be conveyed through safer mechanisms than command-line arguments.

Confidence: 96%Severity: 56%
AnomalyLOW
scripts/export_pptx/lib/image_downloader.mjs

The code appears to implement a legitimate remote-image localization feature. It contains no clear malware, credential theft, backdoor, or obfuscation. However, URLs sourced from page files are fetched without SSRF protections, request timeouts, response-size limits, or content validation. Risk is elevated when page HTML can be supplied or modified by an untrusted party or when the process has access to sensitive internal networks.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 21, 2026, 08:41 AM
Package URL
pkg:socket/skills-sh/opensensenova%2Fsensenova-skills%2Fsn-ppt-standard%2F@3fcc4a30416716eb1307b78141b45b5a33bdd663dac464dd3ff6d107555bb0c7
Security Audit — socket — sn-ppt-standard