
Security News
/Research
Popular node-ipc npm Package Infected with Credential Stealer
Socket detected malicious node-ipc versions with obfuscated stealer/backdoor behavior in a developing npm supply chain attack.
@open-slide/cli
Advanced tools
Scaffold an open-slide workspace with Claude Code skills preconfigured.
Scaffold a workspace for open-slide — a React-based slide framework with Claude Code skills preconfigured.
npx @open-slide/cli init my-slide
cd my-slide
pnpm install
pnpm dev
This creates a workspace containing:
slides/getting-started/ — a starter slide you can edit or delete.package.json — depends on @open-slide/core, which provides the runtime (home page, slide viewer, fullscreen mode) and the open-slide CLI.open-slide.config.ts — optional typed config (slidesDir, port)..claude/skills/ and .agents/skills/ — Claude Code skills (create-slide, apply-comments, …).CLAUDE.md — agent guide for authoring slides.You won't see any Vite, React, or tsconfig files in the workspace. They live inside @open-slide/core and you never touch them.
| Command | Description |
|---|---|
open-slide init [dir] | Scaffold a new workspace in dir (defaults to current dir). |
open-slide init --force | Scaffold into a non-empty directory. |
open-slide init --name <name> | Override the generated package.json name. |
(Once installed in the workspace, @open-slide/core provides open-slide dev, open-slide build, and open-slide preview via its own bin.)
Inside the scaffolded workspace, slides live under slides/<kebab-case-id>/index.tsx and default-export an array of Page components. Each page renders into a fixed 1920×1080 canvas; the framework handles scaling.
Ask Claude Code to "make slides about X" and the create-slide skill will take it from there.
FAQs
Scaffold an open-slide workspace with Claude Code skills preconfigured.
The npm package @open-slide/cli receives a total of 1,519 weekly downloads. As such, @open-slide/cli popularity was classified as popular.
We found that @open-slide/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
Socket detected malicious node-ipc versions with obfuscated stealer/backdoor behavior in a developing npm supply chain attack.

Security News
TeamPCP and BreachForums are promoting a Shai-Hulud supply chain attack contest with a $1,000 prize for the biggest package compromise.

Security News
Packagist urges PHP projects to update Composer after a GitHub token format change exposed some GitHub Actions tokens in CI logs.