Back to skill

Security audit

Ppt Task Orchestrator

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its PPT-to-image delivery purpose, but it needs Review because its delivery settings can write outside the intended folder and may include more generated images than requested.

Review this skill before installing if you handle untrusted PPTX files or request JSON. Use dry-run first, keep delivery.outputDir inside a known safe folder, use a simple ZIP filename with no slashes or traversal, and expect OCR processing plus temporary local copies of slide images.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
lib/delivery.js:35
Finding

Arbitrary File Overwrite Through Unsanitized Delivery ZIP Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code ignores the configured copySelectedOnly behavior and always iterates over all exported PNG paths, which can cause unintended files to be copied into the delivery directory and bundled ZIP. In this orchestration context, that can leak extra generated assets, drafts, or alternate artboards beyond what the caller expected to distribute, creating an information disclosure and over-delivery risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes production orchestration for PPTX page task extraction and batch image delivery by reusing other skills. In this file, the skill spawns local executables (tesseract and swift running Vision OCR) to analyze extracted slide images, which is a materially broader capability than plain PPTX parsing and is not explicitly justified by the stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code invokes external executables ("tesseract" and "swift") to process slide images, which is subprocess execution on user data. Although the function names and comments describe the implementation, there is no user-facing warning, prompt, or visible logging indicating that external OCR tools will be run.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The parser creates a temporary directory and writes extracted slide media files to it, which is a file-write operation involving user-provided presentation content. In this file there is no confirmation prompt, user-facing log/print, or comment disclosing that slide images will be materialized on local disk for OCR processing.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
lib/ppt-parser.js:497