T09 · Insecure Skill Coding Practices
- Location
assets/make_docs.js:307- Finding
Hardcoded lesson-plan output path can overwrite an existing file
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a legitimate Chinese CSP/C++ courseware generator, but it needs review because bundled scripts write to hard-coded local paths and can overwrite files outside the user's chosen folder.
Install only if you are comfortable reviewing or editing the output paths before running the scripts. Run the generators in a dedicated working folder, replace hard-coded C:/Users/ning/... destinations with your chosen output directory, avoid wildcard moves in folders containing unrelated files, and update dependencies before processing untrusted PDFs or images.
assets/make_docs.js:307Hardcoded lesson-plan output path can overwrite an existing file
assets/make_docs.js:563Hardcoded worksheet output path can overwrite an existing file
assets/make_ppt.js:692Hardcoded presentation output path can overwrite an existing file
references/game_template.html:9Offline HTML template makes an undisclosed request to Google Fonts
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
声明描述的是一个功能较完整、可单课或批量生成多种教学资源的课程资料生成技能;而提供的代码片段实际只生成两个 .docx 文档(教案、任务单),且内容是硬编码的单一主题“素数猎人”。这与声明中的主要能力范围存在明显差距。虽然“生成教案和任务单”属于声明能力的子集,但代码没有体现完整套件生成、PDF 批处理、网页游戏、PPT 课件或代码示例等核心宣称能力,因此描述未能准确代表该代码块的实际行为。
声明描述的是一个范围很广的课程资料生成技能,核心能力包括多种文件类型输出、单课与批量处理、以及 PDF 到课程资料的转换。实际代码只实现了其中很窄的一部分:生成一个预设内容的 PPT 课件,并保存到本地路径。代码没有出现任何 DOCX、CPP、HTML、PDF 解析、批量处理或按用户输入动态生成整套资料的逻辑。因此,虽然“生成课件”这一点与声明部分重合,但整体描述明显夸大了实际能力,且主要行为更接近“生成特定单课 PPT 脚本”而不是“完整课程资料套件生成技能”。
Referenced artifact was not completely inspected
以 `references/game_template.html` 为起点:
Referenced artifact was not completely inspected
以 `references/game_template.html` 为起点:
Referenced artifact was not completely inspected
以 `references/game_template.html` 为起点:
This lockfile pins image-size to 1.2.1, and the cited advisories describe denial-of-service conditions via infinite loops in multiple image parsers. In the context of a courseware-generation skill that may process user-supplied or PDF-extracted images when building PPTX assets, a crafted image could hang the process and disrupt automated material generation.
This lockfile includes nanoid 5.1.7, which is flagged for infinite-loop and integer-wraparound issues in certain size-handling paths. While nanoid is typically used for identifier generation rather than direct parsing of attacker files, if any user-controlled size parameter or derived untrusted value reaches non-secure generator calls, it could cause hangs or unstable behavior.
The skill instructs reading and writing local files and organizing outputs into user-specified absolute paths, but it declares no explicit tool scope or permission boundaries. Without declared restrictions, an agent could be induced to access or overwrite unintended files on the host, especially because the workflow includes broad file moves and path handling.
The trigger words include broad everyday phrases such as '做课件' and '做教案', which can cause accidental invocation outside the intended CSP/C++ teaching context. Because the skill's workflow includes file generation and local file handling, mis-triggering can lead to unintended file creation, path prompts, or execution of document-generation steps in unrelated conversations.
The trigger scenarios are overly broad and lack exclusion rules, making activation possible for generic education or content-generation requests. In a skill that proposes installing dependencies, processing PDFs, and writing multiple files, overbroad activation increases the chance of unnecessary or unsafe local operations being initiated in the wrong context.
The file's comments and all generated user-facing document text are written exclusively in Chinese, and the document styling also assumes Chinese fonts and locale conventions. There is no indication that users can choose another language or that this restriction is explicitly documented as a region-specific requirement.
The script generates presentation titles, labels, and messages entirely in Chinese, and the output filename also uses Chinese text. This imposes a specific language/locale without offering user opt-in or documenting that the skill is intentionally region-specific.
This code file contains natural-language documentation entirely in Chinese, including usage and dependency guidance, and later emits Chinese-only CLI messages. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified as region-specific, which is not stated here.
This code performs a file write to a specific absolute path, which can overwrite existing files, but the only disclosure appears after the write succeeds. There is no prior confirmation prompt, warning comment, or docstring explaining that the script will create or replace files at that location.
This line writes another DOCX file directly to a fixed absolute path, which is a safety-relevant file operation. Although success is logged afterward, there is no advance disclosure, confirmation, or inline documentation warning that the script will write this file.
The script writes a generated .pptx to a hard-coded absolute path on the local machine without any validation, configurability, or user confirmation. In an agent/skill context, this can cause unintended file writes, overwrite existing files, fail unpredictably across environments, and leak assumptions about the host filesystem layout.
The dependency uses a caret range (^9.6.1), which allows automatic installation of newer minor/patch releases rather than a fully fixed version. This can introduce supply-chain risk by pulling in unreviewed updates that may contain malicious code, regressions, or newly introduced vulnerabilities during future installs or builds.
{
"dependencies": {
"docx": "^9.6.1",
"pptxgenjs": "^4.0.1"
}
}
The dependency uses a caret range (^4.0.1), which permits future minor/patch versions to be resolved at install time instead of a strictly reviewed version. In a build pipeline that generates courseware artifacts, this increases supply-chain exposure and can lead to non-reproducible builds or introduction of compromised package updates.
{
"dependencies": {
"docx": "^9.6.1",
"pptxgenjs": "^4.0.1"
}
}
Line L0002 sets the document language to "zh-CN", and the visible instructional content throughout the file is written in Chinese with no indication that users may opt into another language. Under the policy rule, forcing a specific language or locale without user choice is a natural-language policy concern.
SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructional content in a single language with no user opt-in, alternative language option, or justification for restricting the skill content to Chinese.
No suspicious patterns detected.