Back to skill

Security audit

powerpoint-generator

Security checks for vulnerabilities and agentic risk

Overview

This presentation skill has a coherent purpose, but it needs review because its setup and rendering pipeline can run broad local code and may expose local files or slide content unexpectedly.

Install only if you are comfortable with a presentation generator that runs local scripts, installs Node/Python packages, renders generated HTML in Chromium, and may use external services for images or visual QA. Avoid using it on confidential decks unless remote visual QA is disabled, dependencies are pinned and installed in an isolated environment, and local image paths are constrained to the presentation asset directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/html_packager.py:26
Finding

Arbitrary Local File Inclusion Through Unrestricted Image Paths

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/subagent_logger.py:65
Finding

Unrestricted Shell Command Execution in Subagent Logger

Content
View full analysis
int: """Execute command and log stdout/stderr.""" write_log(log_path, log_entry(session_id, stage, "command_start", {"command": command})) start_time = time.time() process = subprocess.Popen( command, shell=True, stdout=subprocess.PIPE, stderr=subprocess.PIPE, cwd=str(cwd) if cwd else None, ) ``` The command is exposed directly as a command-line string: ```python # scripts/subagent_logger.py:107 parser.add_argument("--command", help="Command to run (mutually exclusive with --log)") ``` ### Technical Analysis The logger accepts an arbitrary command string and passes it to `subprocess.Popen` with `shell=True`. The operating-system shell therefore interprets metacharacters, substitutions, redirections, pipelines, and chained commands. Although the utility is presented as a runtime logger, it also acts as a general-purpose shell execution interface. If any untrusted value is interpolated into the `--command` string—including a generated filename, user-provided path, stage value, or model-generated argument—an attacker can escape the intended command and execute additional commands. No executable allowlist, argument validation, privilege reduction, or isolation boundary is applied. ### Attack Path 1. An orchestration layer constructs the logger's `--command` value using an attacker-controlled or model-generated value. 2. The attacker includes shell syntax such as command separators, substitutions, redirections, or pipelines. 3. `run_and_log()` forwards the complete string to `subprocess.Popen`. 4. Because `shell=True` is enabled, the shell parses and executes both the intended comma ...[truncated 943 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/html2svg.py:477
Finding

Unpinned Runtime Dependency Installation Bypasses the Lockfile

Content
View full analysis
Installing puppeteer-core...") subprocess.run( ["npm", "install", "puppeteer-core"], capture_output=True, text=True, timeout=60, cwd=str(work_dir) ) # ... if r.returncode != 0: print("Installing dom-to-svg...") subprocess.run( ["npm", "install", "dom-to-svg"], capture_output=True, text=True, timeout=60, cwd=str(work_dir) ) ``` The script also allows `npx` to retrieve and execute a package dynamically: ```python # scripts/html2svg.py:527-533 entry_path.write_text(BUNDLE_ENTRY) r = subprocess.run( ["npx", "-y", "esbuild", str(entry_path), "--bundle", "--format=iife", f"--outfile={bundle_path}", "--platform=browser"], capture_output=True, text=True, timeout=60, cwd=str(work_dir), shell=True ) ``` The mandatory setup documentation similarly installs mutable package versions: ```bash export PUPPETEER_DOWNLOAD_HOST=https://storage.googleapis.com.cnpmjs.org npm install -g puppeteer --unsafe-perm npm install -g dom-to-svg esbuild pip install python-pptx lxml Pillow ``` ### Technical Analysis The repository contains a package lockfile, but conversion scripts install dependencies during execution using package names without exact versions. `npx -y esbuild` may also download and immediately execute a package if a suitable local binary is unavailable. These operations bypass the reviewed lockfile and make the effective dependency set dependent on registry state at execution time. NPM installation can execute lifecycle scripts, while global installation with `--unsafe-perm` increases the impact of such scripts. No evidence was found that the nam ...[truncated 1283 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/html2png.py:111
Finding

Generated HTML Is Rendered With the Chromium Sandbox Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/visual_qa.py:149
Finding

Remote Visual QA Can Disclose Complete Slide Screenshots Without an Explicit Consent Gate

Content
View full analysis
str: """Get API key.""" import os return os.environ.get("OPENAI_API_KEY") or os.environ.get( "VISION_MODEL_API_KEY", "" ) ``` ### Technical Analysis `visual_audit()` reads the complete slide screenshot, Base64-encodes it, and submits it through the OpenAI client. Base64 is standard API transport and is not evidence of covert obfuscation. The security concern is that a full screensh ...[truncated 1587 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (87)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The examples include generic phrases like 'I need to present to my boss about Y' and 'Make training materials,' which strongly overlap with normal workplace conversation. In a multi-skill agent, this increases the chance of accidental routing into this skill when the user may only be asking for advice, summaries, or planning help, potentially triggering extensive autonomous actions.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

文档将技能描述为在用户提到做 PPT、演示、slides、培训材料、路演 deck,甚至“帮我做一个关于 X 的介绍”“我要给老板汇报 Y”等场景下都可触发,范围明显过宽。这会导致普通对话被误判为调用该技能,进而启动多步搜集、生成和文件写出流程,在未充分确认用户意图时执行较重的系统操作。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

示例触发语包含“帮我做个 PPT”“做一个关于 X 的演示”“我要给老板汇报 Y”“做个培训课件”等高度通用表达,这些短语与日常办公交流高度重叠。对代理型技能而言,这种低特异性触发会显著增加误触发概率,使技能在并非明确授权的情况下介入内容生成、资料整理甚至后处理导出。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger conditions are extremely broad, covering many ordinary phrases such as asking for an introduction or something to present to a boss. Broad triggers raise the chance that a high-privilege skill with shell and filesystem behaviors activates in routine conversations where the user did not intend to authorize local execution or file changes.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 516)May include surrounding context.

md
2. **SVG Conversion** -- Run `html2svg.py` (DOM direct to SVG, preserves editable `<text>`)

Known Vulnerable Dependency: basic-ftp==5.2.0 — 4 advisory(ies): GHSA-6v7q-wjvx-w8wg (basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Exe); CVE-2026-39983 (basic-ftp has FTP Command Injection via CRLF); CVE-2026-41324 (basic-ftp vulnerable to denial of service via unbounded memory consumption in Cl) +1 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile includes basic-ftp 5.2.0, which is reported with command-injection and DoS advisories. In this dependency graph it is pulled in transitively via get-uri/pac-proxy-agent/proxy-agent under Puppeteer browser download and proxy handling, so exploitation would generally require attacker influence over FTP/PAC-related inputs or the package's network environment. That still makes it a real supply-chain risk if untrusted URLs or proxy configurations are ever processed.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: extract-zip==2.0.1 — 2 advisory(ies): CVE-2026-19693 (extract-zip allows arbitrary file writes through symlink archive entries); CVE-2026-56876 (extract-zip unvalidated symlink path traversal)

High
Category
Supply Chain
Confidence
94% confidence
Finding

extract-zip 2.0.1 is present through Puppeteer's browser download stack and is reported vulnerable to symlink-based path traversal/arbitrary file write during archive extraction. If the skill installs browsers automatically or processes attacker-influenced ZIP content through this path, exploitation could overwrite files outside the intended directory and potentially lead to code execution or persistent compromise.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: image-size==1.2.1 — 2 advisory(ies): CVE-2025-71329 (image-size: JXL and HEIF parsers allow denial of service through infinite loops); CVE-2025-71330 (image-size: ICNS parser allows denial of service through an infinite loop)

High
Category
Supply Chain
Confidence
92% confidence
Finding

image-size 1.2.1 is used by pptxgenjs and has advisories for infinite-loop DoS in several image parsers. In a presentation-generation skill that likely accepts or fetches user-supplied images, malformed image files could trigger excessive CPU consumption or hangs, making this more relevant than in a purely static application.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.1.0 — 2 advisory(ies): CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco); CVE-2026-42338 (ip-address has XSS in Address6 HTML-emitting methods)

High
Category
Supply Chain
Confidence
80% confidence
Finding

ip-address 10.1.0 is flagged for parsing inconsistencies and XSS in HTML-emitting methods, but here it is only a transitive dependency of socks/socks-proxy-agent under Puppeteer's proxy support. Unless the skill exposes IP formatting output into HTML or makes security decisions from attacker-controlled IP strings via this library, practical exploitability is limited in this context.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
89% confidence
Finding

js-yaml 4.1.1 is present via cosmiconfig in the Puppeteer stack and has CPU consumption advisories on crafted YAML. This is a real dependency risk, though it becomes exploitable only if untrusted YAML/config content is parsed; a skill environment that loads user-influenced config files would raise the danger, while static packaged configs lower it.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==3.3.11 — 3 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
80% confidence
Finding

nanoid 3.3.11 is flagged for edge-case infinite loops and integer handling issues, but these typically depend on unsafe custom or non-secure generator usage with invalid size parameters. In this dependency graph it is a transitive dependency of postcss, and there is no evidence in the lockfile alone that the dangerous APIs are exposed to attacker-controlled inputs.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.5.8 — 4 advisory(ies): CVE-2026-45623 (PostCSS: Arbitrary file read and information disclosure via attacker-controlled ); CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-41305 (PostCSS has XSS via Unescaped </style> in its CSS Stringify Output) +1 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

postcss 8.5.8 is a real vulnerable dependency with advisories including arbitrary file read and XSS in CSS stringification. Because this skill generates HTML presentations and may transform user-influenced styles/content, the context makes output-encoding and parser issues more relevant than in a non-rendering backend, even though actual exploitability depends on how CSS input and source maps are handled.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==7.24.7 — 12 advisory(ies): CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-13697 (undici vulnerable to cross-user information disclosure and parse-time crash via ); CVE-2026-16728 (undici vulnerable to downstream response desynchronization via retry interceptor) +9 more

High
Category
Supply Chain
Confidence
91% confidence
Finding

undici 7.24.7 is a heavily used HTTP client within jsdom and carries multiple advisories affecting request/response handling, disclosure, and desynchronization-style behaviors. A PPT-generation skill that gathers information, fetches assets, or renders remote content increases the chance that network-facing code paths are exercised, making this dependency materially risky if untrusted URLs or remote resources are processed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.