pptx

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] The PPTX automation/documentation fragment represents a legitimate, multi-tool workflow for PPTX creation, editing, and analysis. No explicit malware or exfiltration indicators are present within the fragment. The main security posture concerns stem from supply-chain integrity, script validation, and environment hardening across multiple components. Recommended mitigations: implement input validation and sandboxing for all scripts, enforce least-privilege file system access, pin tool versions, validate and sign generated artifacts, and audit external tool invocations. Overall risk is moderate but manageable with proper controls. LLM verification: The skill fragment aligns superficially with PPTX analysis but lacks concrete implementation details. The presence of dependency installation commands in the static findings suggests potential risk if executed in an automation environment. Overall assessment: SUSPICIOUS (not clearly malicious, but with concerning install-pattern indicators and lack of explicit, verifiable execution logic).

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:41 AM
Package URL
pkg:socket/skills-sh/vibery-studio%2Ftemplates%2Fpptx%2F@5b787c813bc0c51ac50610af904cabdcc5ce91ea