Back to skill

Security audit

Pitch Deck

Security checks for vulnerabilities and agentic risk

Overview

The pitch-deck skill is mostly ordinary, but one bundled helper stores user inputs in local files with weak scoping and misleading deletion behavior.

Review this before installing if you expect strict handling of confidential fundraising or business details. The main generator is local and no exfiltration was found, but avoid putting sensitive information into the generic pitch-deck helper unless you are comfortable with local plaintext history/data files and the current deletion behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Environment-Controlled Persistent File Writes Follow Symbolic Links

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 5–7, 35, and 62–64
Vulnerability Type: Unrestricted storage path and unsafe symbolic-link-following file writes
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${PITCH_DECK_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/pitch-deck}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }
bash
cmd_add() {
    echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo "  Added: $*"
    _log "add" "${1:-}"
}

Technical Analysis

The PITCH_DECK_DIR environment variable completely controls the directory in which the script creates or appends to persistent files. The path is not canonicalized, restricted to an expected user-data directory, or checked for ownership and safe permissions.

The shell redirections used for history.log and data.log follow symbolic links. The script does not verify that either destination is a regular file, reject pre-existing symbolic links, or use a file-opening mechanism that prevents link traversal. It also does not set a restrictive umask, so the confidentiality of newly created files depends on the caller's environment.

Most commands invoke _log, including commands that appear read-only, causing command arguments to be retained persistently. The add command stores all supplied arguments in plaintext in data.log. If users provide confidential business information, that information may consequently be exposed to other accounts where default file permissions are permissive.

Exploitation requires the attacker to control PITCH_DECK_DIR or be able to prepare files in the selected data directory. File-system permissions still apply: the script cannot append to a destination that the invoking account is not permitted to write.

Attack Path

  1. An attacker influences the process environment and sets `PITCH_DECK_DI ...[truncated 1444 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not permit an unrestricted environment variable to select arbitrary write destinations. If configurability is necessary, canonicalize the requested path and verify that it remains beneath an approved per-user data root.
  2. Create the data directory with restrictive permissions:
    bash
    umask 077
    install -d -m 700 -- "$DATA_DIR"
    
  3. Verify that the directory is owned by the invoking user and is not writable by untrusted users.
  4. Reject symbolic links and non-regular destination files before writing. Prefer a small helper implemented with secure file-opening flags such as O_NOFOLLOW, O_APPEND, and O_CREAT, followed by ownership and file-type validation.
  5. Create data and history files with mode 0600, and validate existing files before every append.
  6. Avoid logging command arguments unless they are operationally required. Redact potentially sensitive values and document the retention behavior.
  7. Do not perform persistent writes for read-only commands unless explicit audit logging is a documented feature.
  8. Remove scripts/script.sh if this generic persistence utility is unrelated to the pitch-deck generator's intended functionality.
  9. Ensure the script is never run with elevated privileges unless strictly required.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase '专为中文用户设计,理解中国市场和文化' indicates a locale-specific design preference in natural language. Under the policy, forcing or prescribing a specific language/locale without user opt-in is a reportable issue unless clearly justified as region-specific, which is not documented here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command name and user-facing output indicate that an entry is being removed, but the implementation only echoes a message and writes to the history log. The data file referenced elsewhere by the skill is never updated, so the documented intent of removal contradicts actual behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Line L002 labels the skill in Chinese ("商业计划书/路演PPT生成器") while the file does not state that it is intended only for Chinese-speaking users or provide any language/locale opt-in. This can violate language-choice policy because it imposes a specific language in user-facing natural language without documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown content presents the skill guidance entirely in Chinese with no indication that language selection is optional or that the skill is specifically intended for a Chinese-speaking audience. This creates a natural-language policy concern because it implicitly fixes the locale without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.