T09 · Insecure Skill Coding Practices
- Location
scripts/html_packager.py:26- Finding
Arbitrary Local File Inclusion Through Unrestricted Image Paths
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This presentation skill has a coherent purpose, but it needs review because its setup and rendering pipeline can run broad local code and may expose local files or slide content unexpectedly.
Install only if you are comfortable with a presentation generator that runs local scripts, installs Node/Python packages, renders generated HTML in Chromium, and may use external services for images or visual QA. Avoid using it on confidential decks unless remote visual QA is disabled, dependencies are pinned and installed in an isolated environment, and local image paths are constrained to the presentation asset directory.
scripts/html_packager.py:26Arbitrary Local File Inclusion Through Unrestricted Image Paths
scripts/subagent_logger.py:65Unrestricted Shell Command Execution in Subagent Logger
scripts/html2svg.py:477Unpinned Runtime Dependency Installation Bypasses the Lockfile
scripts/html2png.py:111Generated HTML Is Rendered With the Chromium Sandbox Disabled
scripts/visual_qa.py:149Remote Visual QA Can Disclose Complete Slide Screenshots Without an Explicit Consent Gate
The examples include generic phrases like 'I need to present to my boss about Y' and 'Make training materials,' which strongly overlap with normal workplace conversation. In a multi-skill agent, this increases the chance of accidental routing into this skill when the user may only be asking for advice, summaries, or planning help, potentially triggering extensive autonomous actions.
文档将技能描述为在用户提到做 PPT、演示、slides、培训材料、路演 deck,甚至“帮我做一个关于 X 的介绍”“我要给老板汇报 Y”等场景下都可触发,范围明显过宽。这会导致普通对话被误判为调用该技能,进而启动多步搜集、生成和文件写出流程,在未充分确认用户意图时执行较重的系统操作。
示例触发语包含“帮我做个 PPT”“做一个关于 X 的演示”“我要给老板汇报 Y”“做个培训课件”等高度通用表达,这些短语与日常办公交流高度重叠。对代理型技能而言,这种低特异性触发会显著增加误触发概率,使技能在并非明确授权的情况下介入内容生成、资料整理甚至后处理导出。
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The finding indicates QA/audit of local HTML slides using Puppeteer and an external vision model API, none of which is clearly reflected in the declared purpose. Sending rendered local content to outside services can leak sensitive presentation material, screenshots, or embedded information without informed consent.
The trigger conditions are extremely broad, covering many ordinary phrases such as asking for an introduction or something to present to a boss. Broad triggers raise the chance that a high-privilege skill with shell and filesystem behaviors activates in routine conversations where the user did not intend to authorize local execution or file changes.
Referenced artifact was not completely inspected
2. **SVG Conversion** -- Run `html2svg.py` (DOM direct to SVG, preserves editable `<text>`)
The lockfile includes basic-ftp 5.2.0, which is reported with command-injection and DoS advisories. In this dependency graph it is pulled in transitively via get-uri/pac-proxy-agent/proxy-agent under Puppeteer browser download and proxy handling, so exploitation would generally require attacker influence over FTP/PAC-related inputs or the package's network environment. That still makes it a real supply-chain risk if untrusted URLs or proxy configurations are ever processed.
extract-zip 2.0.1 is present through Puppeteer's browser download stack and is reported vulnerable to symlink-based path traversal/arbitrary file write during archive extraction. If the skill installs browsers automatically or processes attacker-influenced ZIP content through this path, exploitation could overwrite files outside the intended directory and potentially lead to code execution or persistent compromise.
image-size 1.2.1 is used by pptxgenjs and has advisories for infinite-loop DoS in several image parsers. In a presentation-generation skill that likely accepts or fetches user-supplied images, malformed image files could trigger excessive CPU consumption or hangs, making this more relevant than in a purely static application.
ip-address 10.1.0 is flagged for parsing inconsistencies and XSS in HTML-emitting methods, but here it is only a transitive dependency of socks/socks-proxy-agent under Puppeteer's proxy support. Unless the skill exposes IP formatting output into HTML or makes security decisions from attacker-controlled IP strings via this library, practical exploitability is limited in this context.
js-yaml 4.1.1 is present via cosmiconfig in the Puppeteer stack and has CPU consumption advisories on crafted YAML. This is a real dependency risk, though it becomes exploitable only if untrusted YAML/config content is parsed; a skill environment that loads user-influenced config files would raise the danger, while static packaged configs lower it.
nanoid 3.3.11 is flagged for edge-case infinite loops and integer handling issues, but these typically depend on unsafe custom or non-secure generator usage with invalid size parameters. In this dependency graph it is a transitive dependency of postcss, and there is no evidence in the lockfile alone that the dangerous APIs are exposed to attacker-controlled inputs.
postcss 8.5.8 is a real vulnerable dependency with advisories including arbitrary file read and XSS in CSS stringification. Because this skill generates HTML presentations and may transform user-influenced styles/content, the context makes output-encoding and parser issues more relevant than in a non-rendering backend, even though actual exploitability depends on how CSS input and source maps are handled.
undici 7.24.7 is a heavily used HTTP client within jsdom and carries multiple advisories affecting request/response handling, disclosure, and desynchronization-style behaviors. A PPT-generation skill that gathers information, fetches assets, or renders remote content increases the chance that network-facing code paths are exercised, making this dependency materially risky if untrusted URLs or remote resources are processed.
No suspicious patterns detected.