kingdee-ppt

Warn

Audited by Socket on May 9, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/html2pptx.js

This module is primarily an HTML-to-PPTX converter, not an overtly malicious package. However, it is security-relevant because it renders caller-provided local HTML via file:// in a headless browser, extracts image/background paths from that content, and passes resulting (largely unconstrained) filesystem paths directly into the PowerPoint image/background loader. Additionally, it logs browser console output from the rendered page, which can expose sensitive information if attacker-controlled HTML executes scripts. In a threat model where htmlFile/HTML content or referenced asset paths are not fully trusted, the security risk is moderate and should be reviewed with the downstream presentation/media library’s path-handling behavior in mind.

Confidence: 68%Severity: 62%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but its execution trust is not: it runs an unverified global `kingdee-ppt` binary with no confirmed same-org publisher evidence, which is disproportionate supply-chain risk for a presentation skill. Optional Vercel deployment and CDN asset loading are plausible but add third-party data flow outside Kingdee.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
May 9, 2026, 03:44 AM
Package URL
pkg:socket/skills-sh/WayneZhon%2FKingDee-PPT-Skill%2Fkingdee-ppt%2F@9c3f8eca11f94b797375e094e1bb0bf10b60339d