T01 · Skill Instruction Hijacking
- Location
scripts/slides.sh:43- Finding
Unconditional Third-Party Promotional Content in Generated Presentations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is mostly a slide-generation skill, but it includes under-disclosed local history logging and loosely scoped file-reading utilities that users should review before installing.
Review this package before installing. The expected slide-generation commands are local and do not contact the network, but avoid using the extra content-logging script with confidential material unless you are comfortable with raw inputs being stored under ~/.local/share/slide-maker. Only run export/count/timing on intended slide markdown files, and check generated decks for the hard-coded BytesAgain footer before publishing.
scripts/slides.sh:43Unconditional Third-Party Promotional Content in Generated Presentations
"; exit 1; }
grep -v "^---$" "$f" 2>/dev/null;;
```
Related file-processing commands also accept unrestricted paths:
```bash
count)
f="${1:-}"; [ -z "$f" ] && { echo "Usage: count <file>"; exit 1; }
n=$(grep -c "^---$" "$f" 2>/dev/null || echo 0)
echo "Slides: $((n/2 + 1))";;
timing)
f="${1:-}"; min="${2:-15}"
[ -z "$f" ] && { echo "Usage: timing <file> <minutes>"; exit 1; }
n=$(grep -c "^---$" "$f" 2>/dev/null || echo 0)
slides=$((n/2 + 1))
per=$(echo "$min $slides" |
...[truncated 2996 chars]:144Unrestricted Local File Disclosure Through the Export Command
The description claims a presentation/slide deck generator, but the code does not generate presentations or slides at all. Instead, it acts as a CLI logger/notebook for various content-related inputs, saving entries to per-command log files in ~/.local/share/slide-maker and offering analytics/export/search utilities. While an 'outline' command loosely overlaps with presentation planning, the overall command set and behavior are much more aligned with generic content tooling or social/copywriting support than slide creation. The undeclared local data storage, export, and search capabilities are also materially different from the declared purpose.
The manifest describes a presentation and slide deck generator for outlines, full decks, speaker notes, pitch decks, training slides, and report presentations. However, the exposed command set and behavior shown here only records arbitrary text inputs to per-command log files and includes social/content-marketing style operations unrelated to slide generation, indicating a strong mismatch between declared purpose and actual functionality.
The script creates a persistent data directory and later stores user-supplied content there without any up-front notice or consent flow. In a content-generation skill, users may paste sensitive business notes, drafts, or proprietary material, which then remains on disk and can be exposed to other local processes, backup systems, or later exports.
The tool persistently records essentially all user-provided content and then offers built-in search, status, recent, and export operations over that history. In context, a slide-making skill is likely to receive confidential presentation material, internal strategies, customer data, or unreleased plans, so the retention-and-disclosure pathway materially raises confidentiality risk even without network exfiltration.
A slide-maker skill would reasonably support outline creation, deck generation, speaker notes, and related presentation transformations. Commands for scheduling content and producing hashtags, hooks, or calls to action are characteristic of social/media publishing workflows rather than presentation generation, making these capabilities context-inappropriate for the declared scope.
The export feature aggregates all persisted logs into a new file, increasing the concentration and portability of potentially sensitive user content without warning. That makes accidental disclosure easier because a single export file can contain drafts, edits, outlines, and other historical inputs in one place.
The skill description is overly broad and generic, which can cause an agent to invoke this skill in situations where a slide generator is not clearly the right tool. Over-broad routing increases the attack surface for prompt injection and unintended command execution because the skill may be selected on weak semantic matches rather than explicit user intent.
The design guide explicitly recommends "Noto Sans SC (Chinese)" as a font option without offering any user language or locale selection context. This creates a locale-specific preference in the skill output rather than presenting language support as optional or user-driven.
No suspicious patterns detected.