Back to skill

Security audit

Slide Maker

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a slide-generation skill, but it includes under-disclosed local history logging and loosely scoped file-reading utilities that users should review before installing.

Review this package before installing. The expected slide-generation commands are local and do not contact the network, but avoid using the extra content-logging script with confidential material unless you are comfortable with raw inputs being stored under ~/.local/share/slide-maker. Only run export/count/timing on intended slide markdown files, and check generated decks for the hard-coded BytesAgain footer before publishing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Note
Location
scripts/slides.sh:43
Finding

Unconditional Third-Party Promotional Content in Generated Presentations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
"; exit 1; } grep -v "^---$" "$f" 2>/dev/null;; ``` Related file-processing commands also accept unrestricted paths: ```bash count) f="${1:-}"; [ -z "$f" ] && { echo "Usage: count <file>"; exit 1; } n=$(grep -c "^---$" "$f" 2>/dev/null || echo 0) echo "Slides: $((n/2 + 1))";; timing) f="${1:-}"; min="${2:-15}" [ -z "$f" ] && { echo "Usage: timing <file> <minutes>"; exit 1; } n=$(grep -c "^---$" "$f" 2>/dev/null || echo 0) slides=$((n/2 + 1)) per=$(echo "$min $slides" | ...[truncated 2996 chars]:144
Finding

Unrestricted Local File Disclosure Through the Export Command

Content
View full analysis
"; exit 1; } grep -v "^---$" "$f" 2>/dev/null;; ``` Related file-processing commands also accept unrestricted paths: ```bash count) f="${1:-}"; [ -z "$f" ] && { echo "Usage: count "; exit 1; } n=$(grep -c "^---$" "$f" 2>/dev/null || echo 0) echo "Slides: $((n/2 + 1))";; timing) f="${1:-}"; min="${2:-15}" [ -z "$f" ] && { echo "Usage: timing "; exit 1; } n=$(grep -c "^---$" "$f" 2>/dev/null || echo 0) slides=$((n/2 + 1)) per=$(echo "$min $slides" | awk '{printf "%.1f", $1/$2}') echo "Slides: $slides | Time: ${min}min | Per slide: ${per}min";; ``` ### Technical Analysis The `export` command treats its first argument as an unrestricted filesystem path. It does not verify that the resolved target: - Is inside an approved workspace. - Is a regular file. - Has an expected Markdown extension. - Is not a symbolic link. - Represents a slide deck. - Is safe to disclose in command output. `grep -v "^---$" "$f"` reads every line except exact Markdown separator lines and writes the remaining contents to standard output. Consequently, any file readable by the process can be rendered through the nominal slide-export interface. The path is quoted, so no shell command injection was identified in this code. The vulnerability is instead a missing authorization and path-confinement control. Exploitation depends on inducing the user or an agent to invoke the command with a sensitive path. The script does not transmit output over the network automatically. The `count` and `timing` commands expose less information, but they share the same absence of path validation and can reveal limited metadata about arbitrary readable files. ### Attack Path 1. An a ...[truncated 1654 chars]
Remediation
View remediation
/dev/null`. 9. Run the skill with least-privilege filesystem permissions and avoid mounting unrelated secrets into its execution environment. 10. Add tests covering absolute paths, `..` traversal, symbolic links, device files, and paths outside the approved workspace. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims a presentation/slide deck generator, but the code does not generate presentations or slides at all. Instead, it acts as a CLI logger/notebook for various content-related inputs, saving entries to per-command log files in ~/.local/share/slide-maker and offering analytics/export/search utilities. While an 'outline' command loosely overlaps with presentation planning, the overall command set and behavior are much more aligned with generic content tooling or social/copywriting support than slide creation. The undeclared local data storage, export, and search capabilities are also materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a presentation and slide deck generator for outlines, full decks, speaker notes, pitch decks, training slides, and report presentations. However, the exposed command set and behavior shown here only records arbitrary text inputs to per-command log files and includes social/content-marketing style operations unrelated to slide generation, indicating a strong mismatch between declared purpose and actual functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script creates a persistent data directory and later stores user-supplied content there without any up-front notice or consent flow. In a content-generation skill, users may paste sensitive business notes, drafts, or proprietary material, which then remains on disk and can be exposed to other local processes, backup systems, or later exports.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tool persistently records essentially all user-provided content and then offers built-in search, status, recent, and export operations over that history. In context, a slide-making skill is likely to receive confidential presentation material, internal strategies, customer data, or unreleased plans, so the retention-and-disclosure pathway materially raises confidentiality risk even without network exfiltration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A slide-maker skill would reasonably support outline creation, deck generation, speaker notes, and related presentation transformations. Commands for scheduling content and producing hashtags, hooks, or calls to action are characteristic of social/media publishing workflows rather than presentation generation, making these capabilities context-inappropriate for the declared scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The export feature aggregates all persisted logs into a new file, increasing the concentration and portability of potentially sensitive user content without warning. That makes accidental disclosure easier because a single export file can contain drafts, edits, outlines, and other historical inputs in one place.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is overly broad and generic, which can cause an agent to invoke this skill in situations where a slide generator is not clearly the right tool. Over-broad routing increases the attack surface for prompt injection and unintended command execution because the skill may be selected on weak semantic matches rather than explicit user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The design guide explicitly recommends "Noto Sans SC (Chinese)" as a font option without offering any user language or locale selection context. This creates a locale-specific preference in the skill output rather than presenting language support as optional or user-driven.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.