automating-keynote

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/export_keynote_presentation.py

The code appears intended to automate Keynote exports and does not show clear malware behavior. However, it embeds command-line-controlled file paths directly into AppleScript without escaping, allowing crafted paths to potentially modify or inject AppleScript commands when executed. Paths should be safely encoded or passed through a mechanism that avoids string interpolation, and the duplicated export block should be removed.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 16, 2026, 12:30 PM
Package URL
pkg:socket/skills-sh/spillwavesolutions%2Fautomating-mac-apps-plugin%2Fautomating-keynote%2F@aebe8f5ba52dd82c9a9067790f69d51713e641609d997a2dc65d0724d3bbe8d7
Security Audit — socket — automating-keynote