pdf-to-ppt-pack

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
ppt/framework/components/image.js

No malicious payload logic is evident in this module (no network/process execution), but the component is a high-risk HTML string renderer: it embeds caller-controlled fields directly into HTML content, element attributes (`src`, `alt`, `data-step`, `data-hide-step`), and inline `style` attributes without escaping or sanitization. If the consumer inserts the returned string into the DOM using HTML-unsafe methods (e.g., innerHTML) without sanitization, this can lead to XSS/HTML/attribute/style injection. The security of this module heavily relies on upstream sanitization and safe DOM APIs.

Confidence: 75%Severity: 82%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:11 AM
Package URL
pkg:socket/skills-sh/aipoch%2Fmedical-research-skills%2Fpdf-to-ppt-pack%2F@d69d79e51d312b0aba2052c9ffd3275e37c901f7