html-to-pptx
Audited by Socket on Sep 5, 2026
2 alerts found:
Anomalyx2No clear, confirmed malware behavior is visible in the provided fragment. The main security risk is execution of untrusted JavaScript via page.evaluate(prepare_js) and reliance on multiple embedded JS payload constants (_EXTRACT_JS/_ISOLATE_JS/_NEUTRALIZE_JS), whose actual contents are not present here and could be suspicious. Additionally, an optional --no-sandbox mode reduces browser isolation. Treat the fragment as potentially risky primarily due to these code-execution primitives rather than because of visible data theft/exfiltration.
This module is a legitimate-seeming offline conversion tool structurally, but it carries meaningful security/integrity risk: it executes JavaScript in a real Chromium instance against attacker-influenced HTML, and it can disable Chromium sandboxing via an environment variable. Additionally, it dynamically executes a sibling Python module (`exploded_to_pptx.py`), making the workflow highly sensitive to supply-chain tampering. No direct evidence of credential theft or exfiltration is present in the shown fragment, but the unseen JS snippets and imported converter/module implementations could introduce additional behaviors.