Back to skill

Security audit

web-slide

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent HTML slide-generation skill, but its automatic local theme server and unvalidated theme selection create a file-access concern worth review before installing.

Install only if you are comfortable with a slide skill that can read supplied materials, create/edit local HTML files, launch a temporary localhost theme picker, and optionally load chart or animation libraries from CDNs. Validate theme choices against the documented theme IDs and avoid giving it confidential documents unless you intend that content to be incorporated into generated slides.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/theme-server.py:41
Finding

Unvalidated Theme Identifier Can Influence Agent File Access

Content
View full analysis
Remediation
View remediation
1024: self.send_error(413, 'Request body too large') return ``` 6. Make the Agent independently validate `.theme-choice` rather than trusting the server-generated file. ]]>

T03 · Remote Payload Retrieval and Execution

Note
Location
references/base.html:472
Finding

Generated Slides May Execute Remote CDN Scripts Without Integrity Verification

Content
View full analysis
``` `SKILL.md` directs the Agent to uncomment these tags when the corresponding functionality is required. The same dependency pattern appears in `references/components/chart-js.html:6-7` and `references/components/gsap-recipes.html:4-5`. ### Technical Analysis The URLs use HTTPS and pin explicit library versions, which reduces accidental version drift. However, the generated presentation may retrieve and execute JavaScript from third-party CDN infrastructure at viewing time. The tags do not include Subresource Integrity hashes, and no locally bundled fallback or Content Security Policy constrains the retrieved code. Consequently, the effective executable payload is not fully contained in the audited Skill package. If a CDN account, distribution system, origin artifact, or trusted delivery path is compromised, modified JavaScript can execute with the same browser privileges as the presentation. This behavior is optional: the CDN tags are initially comments and are enabled only for presentations requiring Chart.js, GSAP, or ECharts. The README discloses that advanced charts and animations may require an Internet connection, so the network dependency is not hidden. The security concern is the absence of integrity enforcement, not covert exfiltration by the reviewed code. ### Attack Path 1. The Agent generates a slide dec ...[truncated 1255 chars]
Remediation
View remediation
``` 3. Recalculate and review integrity hashes only during controlled dependency upgrades. 4. Maintain an explicit allowlist of approved dependency names, versions, domains, and hashes. 5. Add a restrictive Content Security Policy where compatible with standalone slide operation, limiting scripts and network connections to required sources. 6. Consider generating two delivery modes: - A fully offline, self-contained presentation with vendored dependencies. - An explicitly labeled online presentation using integrity-protected CDN dependencies. 7. Document dependency versions and provenance in a software bill of materials or equivalent release manifest. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (45)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/base.html (reported line 264)May include surrounding context.

html
<div class="slide-viewport">
    <div class="slide-deck" id="slideDeck">
      <!-- ====================================================
           Slide 页面区域(由 Agent 填充)
           每页格式:
           <section class="slide slide--{layout_type}" data-slide="N">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/base.html (reported line 264)May include surrounding context.

html
<div class="slide-viewport">
    <div class="slide-deck" id="slideDeck">
      <!-- ====================================================
           Slide 页面区域(由 Agent 填充)
           每页格式:
           <section class="slide slide--{layout_type}" data-slide="N">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/components/chart-js.html (reported line 1)May include surrounding context.

html
<!--
  Component: chart-js
  Chart.js 集成参考 — 适合复杂图表(多系列/需交互/大数据量)
  Agent 参考此文件,在 slide--chart 的 .chart-container 中生成 canvas + 初始化脚本

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/components/chart-js.html (reported line 1)May include surrounding context.

html
<!--
  Component: chart-js
  Chart.js 集成参考 — 适合复杂图表(多系列/需交互/大数据量)
  Agent 参考此文件,在 slide--chart 的 .chart-container 中生成 canvas + 初始化脚本

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/components/chart-svg.html (reported line 1)May include surrounding context.

html
<!--
  Component: chart-svg
  SVG 内嵌图表参考 — 适合简单图表(数据点 ≤ 8)
  Agent 参考此文件的写法,根据实际数据生成 SVG 图表代码

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/components/chart-svg.html (reported line 1)May include surrounding context.

html
<!--
  Component: chart-svg
  SVG 内嵌图表参考 — 适合简单图表(数据点 ≤ 8)
  Agent 参考此文件的写法,根据实际数据生成 SVG 图表代码

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/components/gsap-recipes.html (reported line 1)May include surrounding context.

html
<!--
  Component: gsap-recipes
  GSAP 高级动画配方 — Agent 在需要复杂动画时参考
  前提:在 HTML 底部取消注释 GSAP CDN:

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/components/gsap-recipes.html (reported line 1)May include surrounding context.

html
<!--
  Component: gsap-recipes
  GSAP 高级动画配方 — Agent 在需要复杂动画时参考
  前提:在 HTML 底部取消注释 GSAP CDN:

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/components/gsap-recipes.html (reported line 55)May include surrounding context.

html
</script>


<!-- ============================================================
     配方 3:打字机效果(Typewriter)
     适用于标题页或引用页的文字逐字显示
     ============================================================ -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/components/gsap-recipes.html (reported line 55)May include surrounding context.

html
</script>


<!-- ============================================================
     配方 3:打字机效果(Typewriter)
     适用于标题页或引用页的文字逐字显示
     ============================================================ -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/theme-picker.html (reported line 222)May include surrounding context.

html
<p>点击卡片选择,然后点击底部按钮确认</p>
</div>

<!-- ============================================================
     Pure — 极致简约 / 精密排版
     ============================================================ -->
<div class="style-row">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/theme-picker.html (reported line 300)May include surrounding context.

html
</div>
</div>

<!-- ============================================================
     Warm — 暖调学院 / 衬线标题
     ============================================================ -->
<div class="style-row">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/theme-picker.html (reported line 456)May include surrounding context.

html
</div>
</div>

<!-- ============================================================
     Data — 数据可视化
     ============================================================ -->
<div class="style-row">

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation guidance is broad enough that ordinary conversations about slides, presentations, or PPTs may automatically trigger the skill without clear user intent to invoke it. In a skill that can ingest user materials and generate/share HTML output, over-triggering increases the chance of unnecessary processing of sensitive content or unintended actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README encourages users to provide documents, links, screenshots, PDFs, and other reference files but does not warn that their contents may be parsed, transformed, and incorporated into generated HTML. This creates a transparency and privacy risk: users may unknowingly expose confidential information or copyrighted material that is then embedded into output or sent through downstream processing paths.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill requests impactful capabilities including file_write and web_fetch/network-like access but does not define any explicit tool scope boundaries such as allowed tools, permitted paths, or network destinations. That makes the runtime behavior overly permissive and increases the chance of unintended file modification, arbitrary local file edits, or uncontrolled outbound access when the skill is triggered.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger description is very broad and covers common presentation-related requests, which can cause the skill to activate in situations where a user did not specifically intend to invoke a slide-generation workflow. In a skill with file-writing, preview, and network capabilities, overbroad activation expands the attack surface and can lead to unnecessary file creation, web fetching, or other side effects on loosely related requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file consistently defines the skill in Chinese and provides all operational instructions in Chinese, with no indication that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to delete files, start a local Python server, poll for files, open a browser preview, and write output files, but it does not require a user-facing warning or consent for these system-affecting actions. This is risky because the user may be unaware that local state will be modified or that subprocess/network-like behavior will occur as part of theme selection and generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML root sets lang="zh-CN", and the surrounding comments and UI labels are written in Chinese, which indicates the skill is fixed to a specific language/locale. Under the policy, this is a natural-language locale constraint that should either be user-selectable or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions and examples are written as mandatory guidance to the agent in Chinese, including imperative statements about how the agent must use the file. There is no indication that the language is optional, user-selected, or justified as a region-specific constraint, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instructions describe the component behavior and agent actions entirely in Chinese, which can impose a language/locale expectation on downstream use without user opt-in. The file does not indicate that this is a region-specific skill or provide an option to use another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guideline explicitly instructs the agent to delete an existing local file (.theme-choice) automatically as part of its default workflow, without any user confirmation or safety boundary. Even though the target file is narrow and appears to be an app-specific state file, normalizing unattended local file deletion is dangerous because it can remove user or workspace state and sets a precedent for destructive actions in a content-generation skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs the agent to write complete HTML files and later perform in-place edits by inserting content before a closing tag, but it does not require backup, confirmation, path restriction, or overwrite safeguards. In a file-capable agent, this can lead to silent data loss or corruption if the wrong file is targeted, especially during iterative generation where repeated edits modify an existing artifact.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s natural-language instructions and placeholders are written exclusively in Chinese, including directives aimed at the agent. This imposes a specific language/locale without indicating user choice or a region-specific constraint, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.