critical
suspicious.dangerous_exec
- Location
- skills/sn-ppt-standard/scripts/export_pptx/html_to_pptx.mjs:24
- Finding
- Shell command execution detected (child_process).
- Evidence
execSync('npm install --omit=dev', { cwd: __dirname, stdio: 'inherit' });
AdvisoryAudited by Static analysis on May 14, 2026.
Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal, suspicious.prompt_injection_instructions
execSync('npm install --omit=dev', { cwd: __dirname, stdio: 'inherit' });api_key=[REDACTED],
api_key = [REDACTED]
If missing, use inline fallback system prompt:
- System prompt: `prompts/resume.md`