automating-keynote
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyscripts/export_keynote_presentation.py
LOWAnomalyLOW
scripts/export_keynote_presentation.py
The code appears intended to automate Keynote exports and does not show clear malware behavior. However, it embeds command-line-controlled file paths directly into AppleScript without escaping, allowing crafted paths to potentially modify or inject AppleScript commands when executed. Paths should be safely encoded or passed through a mechanism that avoids string interpolation, and the duplicated export block should be removed.
Confidence: 98%Severity: 68%
Audit Metadata