PPT Generator Pro

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The specification accomplishes its stated goal (automated PPT image/video generation + local assembly). The main security concern is supply-chain and privacy: prompts, documents, and full image frames are sent to third-party monetization/proxy endpoints (proxy-monetize.fluxapay.xyz and monetize.fluxapay.xyz), and the agent-pay model requests autonomous access to the user's FluxA Agent Wallet. These practices create a moderate security risk (data exposure and unexpected charges). There is no evidence of executable malware or obfuscated backdoors in the provided spec. Recommendations: do not grant agent-pay wallet access without careful review; prefer direct vendor apikey flows or user-mediated payments; avoid sending sensitive documents to unvetted proxies; require documented privacy/retention policies from any intermediary.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 12:12 PM
Package URL
pkg:socket/skills-sh/fluxa-agent-payment%2Fskills%2Fppt-generator-pro%2F@b61ed93cc7f5629d05985ad8e9a8db6c6e4b897c