Back to skill

Security audit

CSP课件制作技能

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Chinese CSP/C++ courseware generator, but it needs review because bundled scripts write to hard-coded local paths and can overwrite files outside the user's chosen folder.

Install only if you are comfortable reviewing or editing the output paths before running the scripts. Run the generators in a dedicated working folder, replace hard-coded C:/Users/ning/... destinations with your chosen output directory, avoid wildcard moves in folders containing unrelated files, and update dependencies before processing untrusted PDFs or images.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
assets/make_docs.js:307
Finding

Hardcoded lesson-plan output path can overwrite an existing file

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
assets/make_docs.js:563
Finding

Hardcoded worksheet output path can overwrite an existing file

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
assets/make_ppt.js:692
Finding

Hardcoded presentation output path can overwrite an existing file

Content
View full analysis
console.log("PPT 小学趣味版生成成功!")) .catch(e => console.error(e)); ``` ### Technical Analysis The presentation generator sends a fixed absolute filename to `pptxgenjs` instead of accepting the user-approved output directory. There is no validation that the target is inside the intended workspace and no explicit check for a pre-existing presentation. The `_v2` suffix reduces the likelihood of a collision but does not prevent one. If the library and filesystem permit replacement, an existing same-named presentation can be overwritten. Otherwise, execution can fail because the developer-specific directory does not exist. ### Attack Path 1. A user or agent runs `assets/make_ppt.js` as distributed. 2. The script constructs the presentation in memory. 3. It attempts to save the result to the fixed developer directory. 4. A writable same-named presentation may be replaced without user confirmation. 5. If the directory is missing or inaccessible, the requested presentation is not produced. ### Impact Assessment The write is constrained by the permissions of the Node.js process and does not grant additional privileges. The affected scope is the hardcoded destination and any existing file with the same name. Potential consequences include accidental presentation loss, writes outside the selected project directory, local path disclosure, and failed generation on other systems. ]]>
Remediation
View remediation

other

Note
Location
references/game_template.html:9
Finding

Offline HTML template makes an undisclosed request to Google Fonts

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

声明描述的是一个功能较完整、可单课或批量生成多种教学资源的课程资料生成技能;而提供的代码片段实际只生成两个 .docx 文档(教案、任务单),且内容是硬编码的单一主题“素数猎人”。这与声明中的主要能力范围存在明显差距。虽然“生成教案和任务单”属于声明能力的子集,但代码没有体现完整套件生成、PDF 批处理、网页游戏、PPT 课件或代码示例等核心宣称能力,因此描述未能准确代表该代码块的实际行为。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个范围很广的课程资料生成技能,核心能力包括多种文件类型输出、单课与批量处理、以及 PDF 到课程资料的转换。实际代码只实现了其中很窄的一部分:生成一个预设内容的 PPT 课件,并保存到本地路径。代码没有出现任何 DOCX、CPP、HTML、PDF 解析、批量处理或按用户输入动态生成整套资料的逻辑。因此,虽然“生成课件”这一点与声明部分重合,但整体描述明显夸大了实际能力,且主要行为更接近“生成特定单课 PPT 脚本”而不是“完整课程资料套件生成技能”。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
以 `references/game_template.html` 为起点:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
以 `references/game_template.html` 为起点:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

md
以 `references/game_template.html` 为起点:

Known Vulnerable Dependency: image-size==1.2.1 — 2 advisory(ies): CVE-2025-71329 (image-size: JXL and HEIF parsers allow denial of service through infinite loops); CVE-2025-71330 (image-size: ICNS parser allows denial of service through an infinite loop)

High
Category
Supply Chain
Confidence
97% confidence
Finding

This lockfile pins image-size to 1.2.1, and the cited advisories describe denial-of-service conditions via infinite loops in multiple image parsers. In the context of a courseware-generation skill that may process user-supplied or PDF-extracted images when building PPTX assets, a crafted image could hang the process and disrupt automated material generation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==5.1.7 — 2 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
90% confidence
Finding

This lockfile includes nanoid 5.1.7, which is flagged for infinite-loop and integer-wraparound issues in certain size-handling paths. While nanoid is typically used for identifier generation rather than direct parsing of attacker files, if any user-controlled size parameter or derived untrusted value reaches non-secure generator calls, it could cause hangs or unstable behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill instructs reading and writing local files and organizing outputs into user-specified absolute paths, but it declares no explicit tool scope or permission boundaries. Without declared restrictions, an agent could be induced to access or overwrite unintended files on the host, especially because the workflow includes broad file moves and path handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger words include broad everyday phrases such as '做课件' and '做教案', which can cause accidental invocation outside the intended CSP/C++ teaching context. Because the skill's workflow includes file generation and local file handling, mis-triggering can lead to unintended file creation, path prompts, or execution of document-generation steps in unrelated conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger scenarios are overly broad and lack exclusion rules, making activation possible for generic education or content-generation requests. In a skill that proposes installing dependencies, processing PDFs, and writing multiple files, overbroad activation increases the chance of unnecessary or unsafe local operations being initiated in the wrong context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's comments and all generated user-facing document text are written exclusively in Chinese, and the document styling also assumes Chinese fonts and locale conventions. There is no indication that users can choose another language or that this restriction is explicitly documented as a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script generates presentation titles, labels, and messages entirely in Chinese, and the output filename also uses Chinese text. This imposes a specific language/locale without offering user opt-in or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language documentation entirely in Chinese, including usage and dependency guidance, and later emits Chinese-only CLI messages. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code performs a file write to a specific absolute path, which can overwrite existing files, but the only disclosure appears after the write succeeds. There is no prior confirmation prompt, warning comment, or docstring explaining that the script will create or replace files at that location.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This line writes another DOCX file directly to a fixed absolute path, which is a safety-relevant file operation. Although success is logged afterward, there is no advance disclosure, confirmation, or inline documentation warning that the script will write this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script writes a generated .pptx to a hard-coded absolute path on the local machine without any validation, configurability, or user confirmation. In an agent/skill context, this can cause unintended file writes, overwrite existing files, fail unpredictably across environments, and leak assumptions about the host filesystem layout.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency uses a caret range (^9.6.1), which allows automatic installation of newer minor/patch releases rather than a fully fixed version. This can introduce supply-chain risk by pulling in unreviewed updates that may contain malicious code, regressions, or newly introduced vulnerabilities during future installs or builds.

Content

Scanner excerpt · assets/package.json (reported line 3)May include surrounding context.

json
{
  "dependencies": {
    "docx": "^9.6.1",
    "pptxgenjs": "^4.0.1"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency uses a caret range (^4.0.1), which permits future minor/patch versions to be resolved at install time instead of a strictly reviewed version. In a build pipeline that generates courseware artifacts, this increases supply-chain exposure and can lead to non-reproducible builds or introduction of compromised package updates.

Content

Scanner excerpt · assets/package.json (reported line 4)May include surrounding context.

json
{
  "dependencies": {
    "docx": "^9.6.1",
    "pptxgenjs": "^4.0.1"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L0002 sets the document language to "zh-CN", and the visible instructional content throughout the file is written in Chinese with no indication that users may opt into another language. Under the policy rule, forcing a specific language or locale without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructional content in a single language with no user opt-in, alternative language option, or justification for restricting the skill content to Chinese.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.