T09 · Insecure Skill Coding Practices
- Location
scripts/generate_deck.py:43- Finding
Insufficiently Disclosed Transmission of Presentation Content to Third-Party APIs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This PPT-building skill mostly does what it says, but it can send full slide prompts to third-party image APIs while also claiming there is no external SaaS dependency.
Install only if you are comfortable sending slide prompts and deck content to Ofox or OpenRouter. Do not use it for confidential, regulated, customer, financial, or unreleased business material unless you have approval and understand the provider's data handling. Use a virtual environment and pin dependencies before installing python-pptx.
scripts/generate_deck.py:43Insufficiently Disclosed Transmission of Presentation Content to Third-Party APIs
SKILL.md:239Unpinned Third-Party Dependency Installation
The skill claims an end-to-end workflow and 'no external SaaS dependency' while the instructions explicitly rely on external API gateways/providers such as Ofox/OpenRouter and a Gemini-based image model. This mismatch is security-relevant because operators may trust the skill with sensitive deck content under false assumptions about local-only processing, data handling, and review coverage.
The skill instructs deletion of files as part of a rerun workflow using a raw shell command. Even though the example path is fixed, patterns that normalize destructive shell operations in agent skills are dangerous because parameterization, path substitution, or user-influenced filenames elsewhere in the workflow can lead to unintended deletion of arbitrary files.
python3 scripts/generate_deck.py --start 1 --end 5
# 4. 重跑某页(删旧图再跑)
rm scripts/output/slide_03.jpg && python3 scripts/generate_deck.py --start 3 --end 3
# 5. 生成完自动组装 PPTX
python3 scripts/generate_deck.py --assemble
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
python3 generate_deck.py --start 1 --end 5
# 重跑某一页(先删旧图)
rm output/slide_03.jpg && python3 generate_deck.py --start 3 --end 3
"""
import json
The skill describes capabilities that involve environment access, local file reads, and network/API use, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an overbroad execution surface where an agent may use more tools than intended, making accidental data access or exfiltration harder to constrain and audit.
The primary skill description is written in Chinese and the workflow later explicitly requires '中文渲染强制要求', indicating a fixed language/locale behavior. The file does not offer the user an opt-in choice of language or explain that the skill is intended only for a Chinese-language context.
The global prompt requirements explicitly include a mandatory Chinese-rendering requirement, which imposes a specific language/locale on outputs. Because the document does not provide a user choice or a justified China-specific compliance/business constraint, this is a natural-language policy violation under the language/locale rule.
The instruction '所有中文文字必须清晰可读' mandates Chinese text rendering as a requirement. Elsewhere the guide repeatedly enforces Chinese-only content handling, but it does not offer an opt-in choice or explain that this skill is intentionally limited to a Chinese-language workflow.
The instruction '纯中文' requires a specific language for generated content, which is a natural-language locale policy constraint. The file does not offer the user a language choice or explain a region-specific reason for forcing Chinese output.
This markdown file is entirely written in Chinese and presents the checklist as the default operating language, with no indication that users may choose another language or that the skill is limited to a Chinese-language context. Under the policy rule for natural-language violations, forcing a specific language without opt-in is a reportable issue.
The script sends slide prompts to third-party services (Ofox/OpenRouter) for image generation, and those prompts may contain confidential business content, personal data, or sensitive draft material. Because there is no explicit notice, consent flow, or redaction guidance, users may unintentionally exfiltrate sensitive information off-host.
This code performs outbound transmission to an external image-generation API, carrying user-supplied prompt content and authentication credentials. In the context of a deck-building skill, prompts can easily include proprietary roadmap details, internal strategy, or personal information, so the external transmission is security-relevant and should be treated as data exfiltration risk unless clearly disclosed and controlled.
"response_format": "b64_json"
}).encode("utf-8")
req = urllib.request.Request(
"https://api.ofox.ai/v1/images/generations",
data=payload,
headers={"Content-Type": "application/json", "Authorization": f"Bearer {api_key}"}
)
The requirement to copy source text exactly, combined with the surrounding Chinese-rendering rules, implies a rigid language/locale constraint. The document does not state that this is a Chinese-specific tool or provide any mechanism for users to select another language.
The document is entirely written in Chinese and presents mandatory writing rules such as banned terms and required placeholder formats, but it does not state that the skill is intended only for Chinese-language content or offer any language/locale opt-in. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.
The natural-language interface exposed by the module docstring, usage text, and CLI help strings is fixed to Chinese. This can violate language/locale policy when the skill does not provide users a choice of language or clearly document that it is intentionally region- or locale-specific.
The style string is written as an instruction in Chinese and explicitly requires that all Chinese text be clearly readable, which imposes a specific language/locale expectation. The file does not offer any user choice or opt-in for language, so this is a natural-language locale policy issue.
No suspicious patterns detected.