create-pptx

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is broadly coherent with its stated purpose: it targets PPTX creation, editing, extraction, validation, and QA using well-known tooling (pptxgenjs, markitdown, LibreOffice, Poppler). Data flows are primarily file-based with local outputs (PPTX, images, PDFs, MD files). There are no evident credential reads or exfiltration channels, and no autonomous real-world actions beyond file processing. The only notable concern is the mix of multiple toolchains and potential for untrusted inputs in shell commands; this is a moderate risk rather than a direct threat, and can be mitigated with proper input sanitization, environment pinning, and clear execution boundaries. Overall, the risk is BENIGN with some MEDIUM considerations for supply-chain hygiene and input handling.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 04:46 PM
Package URL
pkg:socket/skills-sh/alexander-kastil%2Fagentic-sw-engineering%2Fcreate-pptx%2F@1a74f7f76b144be517b5aa8d8e9efb5c974da928