T09 · Insecure Skill Coding Practices
- Location
lib/delivery.js:35- Finding
Arbitrary File Overwrite Through Unsanitized Delivery ZIP Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly matches its PPT-to-image delivery purpose, but it needs Review because its delivery settings can write outside the intended folder and may include more generated images than requested.
Review this skill before installing if you handle untrusted PPTX files or request JSON. Use dry-run first, keep delivery.outputDir inside a known safe folder, use a simple ZIP filename with no slashes or traversal, and expect OCR processing plus temporary local copies of slide images.
lib/delivery.js:35Arbitrary File Overwrite Through Unsanitized Delivery ZIP Path
The code ignores the configured copySelectedOnly behavior and always iterates over all exported PNG paths, which can cause unintended files to be copied into the delivery directory and bundled ZIP. In this orchestration context, that can leak extra generated assets, drafts, or alternate artboards beyond what the caller expected to distribute, creating an information disclosure and over-delivery risk.
The manifest describes production orchestration for PPTX page task extraction and batch image delivery by reusing other skills. In this file, the skill spawns local executables (tesseract and swift running Vision OCR) to analyze extracted slide images, which is a materially broader capability than plain PPTX parsing and is not explicitly justified by the stated purpose.
The code invokes external executables ("tesseract" and "swift") to process slide images, which is subprocess execution on user data. Although the function names and comments describe the implementation, there is no user-facing warning, prompt, or visible logging indicating that external OCR tools will be run.
The parser creates a temporary directory and writes extracted slide media files to it, which is a file-write operation involving user-provided presentation content. In this file there is no confirmation prompt, user-facing log/print, or comment disclosing that slide images will be materialized on local disk for OCR processing.
Detected: suspicious.dangerous_exec