cropfig

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
export_deck.py

The code appears intended for local presentation-to-PDF conversion and slide splitting, with no clear malicious behavior or data exfiltration. It contains a moderate security issue because user-controlled filesystem paths are inserted unescaped into an osascript AppleScript command, enabling potential AppleScript injection under macOS if an attacker controls those paths. The macOS PowerPoint path is also broken due to an undefined function, and the supplied fragment appears syntactically incomplete.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 9, 2026, 09:21 AM
Package URL
pkg:socket/skills-sh/youngeun1209%2Foh-my-codex-research%2Fcropfig%2F@12e875fd253c7407af44b551d0b4c9dd67ae7242b92ee0f4eb25a863a57e214d
Security Audit — socket — cropfig