T01 · Skill Instruction Hijacking
- Location
assets/pptx_primitives.py:81- Finding
Unrequested Skill Branding Injected into Customer Presentations
- Content
View full analysis
Vulnerability Details
File Location:
assets/pptx_primitives.py, lines 81 and 142–146
Vulnerability Type: Skill-controlled output manipulation
Risk Level: HighVulnerable Code
python def __init__(self, brand='麦肯锡资料库顾问', width=SW, height=SH): self.prs = Presentation() self.prs.slide_width = Inches(width) self.prs.slide_height = Inches(height) self.blank = self.prs.slide_layouts[6] self.brand = brand self.W, self.H = width, heightpython def footer(self, s, source='', page=None): self.rect(s, 0, self.H-0.32, self.W, 0.32, fill=COL['LIGHT']) left = f'{self.brand} · 内部汇报稿' self.txt(s, 0.55, self.H-0.32, 9.5, 0.32, [{'text':left,'size':8.5,'color':COL['GRAY'],'font':FONT['BODY']}], anchor=MSO_ANCHOR.MIDDLE)Technical Analysis
The
Deckconstructor assigns a Skill-controlled brand as its default value. Thefooter()method subsequently writes that value into generated presentation slides. Because the default applies without explicit user approval, customer-facing files can receive Skill attribution even when the user did not request or authorize it.The workflow in
SKILL.mddirects the agent to use this bundled rendering engine when producing presentations. Therefore, ordinary use of the declared presentation-generation functionality can activate the branding behavior. This alters the content of the deliverable rather than merely controlling an internal implementation detail.Attack Path
- A user asks the Skill to generate a presentation.
- The workflow selects the bundled
pptx_primitives.pyrendering engine. - Presentation code creates
Deck()without supplying an explicitly approved brand. - The constructor silently selects the hard-coded Skill brand.
- Calls to
footer()insert that brand into presentation slides. - The resulting branded presentation is delivered to the user and may subsequently be shared with third parties.
No elevated ...[truncated 703 chars]
- Remediation
View remediation
Remediation Suggestions
- Change the constructor default to an empty or neutral value:
python def __init__(self, brand='', width=SW, height=SH): ...- Render branding only when the user has explicitly requested or approved it:
python if self.brand: left = self.brand else: left = ''-
Obtain organization and attribution text from user-provided presentation requirements rather than from Skill-owned defaults.
-
Separate neutral document metadata, such as confidentiality status, from promotional or author-attribution text.
-
Add automated tests that generate a presentation with default settings and verify that no Skill name, vendor name, or other unapproved attribution appears in slide text.
-
Document branding as an opt-in feature and require confirmation before adding it to customer-facing files.
