ppt-component-atlas

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/export-component-html.mjs

No clear indicators of hidden backdoors or active malware execution are present in this module. The dominant security issue is supply-chain and content-injection risk: the script embeds catalog-provided HTML snippets and CSS verbatim into exported HTML files without sanitization or allowlisting. If an attacker can compromise the catalog content (local file or remote source used to generate/compare), the produced artifacts could enable XSS or other browser-side abuse when opened. Verification compares content but does not establish authenticity/pinning for the remote data, leaving the tool vulnerable to tampered inputs from a supply-chain perspective.

Confidence: 74%Severity: 62%
Audit Metadata
Analyzed At
Jul 16, 2026, 08:05 AM
Package URL
pkg:socket/skills-sh/WiseWong6%2Fwise-skills%2Fppt-component-atlas%2F@fa93ab563130da7aa2b7335022888159ec8ea197
Security Audit — socket — ppt-component-atlas