Back to skill

Security audit

PPTX · HTML 演示与可编辑文字导出

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local PPTX-generation skill whose file access, browser rendering, and maintenance audit behavior are disclosed and aligned with its purpose.

Use this skill only when you are comfortable with a local presentation tool that writes project files, launches a headless browser, and may run maintenance audits when the skill itself is changed. Keep work in an intended project directory and avoid running maintenance audit commands unless you are modifying the skill package.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (74)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill describes package-manifest generation and audit operations that traverse files, read contents, compute hashes, and write integrity metadata, yet these broader integrity-audit capabilities are not surfaced in the top-level skill metadata. Hidden filesystem inventory and hashing behavior can expose sensitive local data and expands the trust boundary beyond ordinary presentation generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill describes package-manifest generation and audit operations that traverse files, read contents, compute hashes, and write integrity metadata, yet these broader integrity-audit capabilities are not surfaced in the top-level skill metadata. Hidden filesystem inventory and hashing behavior can expose sensitive local data and expands the trust boundary beyond ordinary presentation generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill describes package-manifest generation and audit operations that traverse files, read contents, compute hashes, and write integrity metadata, yet these broader integrity-audit capabilities are not surfaced in the top-level skill metadata. Hidden filesystem inventory and hashing behavior can expose sensitive local data and expands the trust boundary beyond ordinary presentation generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill describes package-manifest generation and audit operations that traverse files, read contents, compute hashes, and write integrity metadata, yet these broader integrity-audit capabilities are not surfaced in the top-level skill metadata. Hidden filesystem inventory and hashing behavior can expose sensitive local data and expands the trust boundary beyond ordinary presentation generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill describes package-manifest generation and audit operations that traverse files, read contents, compute hashes, and write integrity metadata, yet these broader integrity-audit capabilities are not surfaced in the top-level skill metadata. Hidden filesystem inventory and hashing behavior can expose sensitive local data and expands the trust boundary beyond ordinary presentation generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill describes package-manifest generation and audit operations that traverse files, read contents, compute hashes, and write integrity metadata, yet these broader integrity-audit capabilities are not surfaced in the top-level skill metadata. Hidden filesystem inventory and hashing behavior can expose sensitive local data and expands the trust boundary beyond ordinary presentation generation.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
机器规则为 [pptx-audit-rules.json](references/pptx-audit-rules.json),底层工具为 `scripts/pptx_audit.py`。仅在技能维护或用户明确要求检查某个成品时调用。审计检查文本层级、字体、源文字、真实行间相交、溢出和前景遮挡;检查器只读输入,不缩字、

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
[在线浏览 Agents 演示稿](https://fuetsui.github.io/pptx/Agents.html);离线样本:[references/Agents.html](references/Agents.html)。样本展示 HTML 演示效果,不能作为完整的逐页源码项目继续构建。技能源码和安装说明见

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/audit_skill.py (reported line 87)May include surrounding context.

python
run_id = datetime.now(timezone.utc).strftime("%Y%m%dT%H%M%SZ-") + uuid.uuid4().hex[:8]
    run_dir = output / "runs" / run_id; run_dir.mkdir(parents=True)
    report_path = output / "skill-audit.json"
    env = os.environ.copy(); env["PYTHONDONTWRITEBYTECODE"] = "1"
    if chrome:
        env["CHROME_BIN"] = str(Path(chrome).expanduser().resolve())
    sys.dont_write_bytecode = True

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to run shell commands, read and write project files, and potentially access external references/GitHub, but it declares no tool restrictions or permission scope. This creates an overly broad execution surface where a caller or compromised workflow could induce unintended filesystem, environment, or network access beyond what is necessary for slide generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The short description and default prompt are written entirely in Chinese and imply the skill operates in that language, but the file does not indicate this is optional or limited to a justified Chinese-only context. This can violate language/locale policy when users are not given an explicit choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The body selector applies var(--font-zh) globally, which enforces a Chinese-oriented font stack for all rendered content. The file does not offer any user opt-in or alternative locale selection, and no region-specific justification is provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The selector .slide [data-text-role] sets font-family:var(--font-zh)!important for semantic text roles, which imposes a specific locale/font choice on all slide text. This is a natural-language policy concern because it removes language or locale choice without visible opt-in or justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest sets lang to zh-CN, which forces a specific language/locale. Under the policy, locale constraints should either offer user choice or be clearly documented and justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document root sets lang="zh-CN", and the template content is written in Chinese, which imposes a specific language/locale on all consumers of this skill output. There is no indication in the file that the locale is optional, user-selectable, or justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L25 instructs the user to '先用一句中文写清', which mandates Chinese as the input language. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file contains user-facing operational instructions exclusively in Chinese, which can effectively force a specific language on users or maintainers. The policy allows locale-specific behavior only when there is user opt-in or a clearly justified regional constraint, neither of which is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file repeatedly specifies that the maintenance flow creates and tests Chinese sample content, e.g. '两页中文 HTML 样稿'. This is a natural-language locale constraint, and the document does not provide user opt-in, alternatives, or a clear justification that the skill is intentionally limited to a Chinese-only regional/compliance context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The regression section says the tests automatically generate and audit a '正常中文两页稿', which indicates the validation regime is tied to a specific language. Because no alternative locales or opt-in behavior are described, this appears to violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions exclusively in Chinese and does not mention any user opt-in, language selection, or locale-specific justification. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire troubleshooting guidance is written only in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/audit_skill.py (reported line 64)May include surrounding context.

python
def _cli(args: list[str], run_dir: Path, sequence: int, env: dict) -> dict:
    command = [sys.executable, "-X", "utf8", str(SCRIPTS / "pptx_cli.py"), *args, "--compact"]
    completed = subprocess.run(command, cwd=run_dir, env=env, capture_output=True, text=True, encoding="utf-8", errors="replace", timeout=240)
    log = run_dir / f"command-{sequence:02d}.json"
    try:
        payload = json.loads(completed.stdout)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The build output filename is hard-coded as Chinese ("演示文稿.html") and the generated HTML defaults to lang="zh-CN" when no language is provided. This imposes a specific language/locale choice by default, and the file does not offer user opt-in or document a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated HTML sets lang="zh-CN", which forces a specific locale in the output. The file also contains Chinese-only user-facing content, but there is no visible opt-in, locale selection, or documented region-specific justification in this skill file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code executes external system commands to terminate browser processes, including pkill on POSIX and taskkill on Windows, and later launches Chrome via subprocess.Popen. These are safety-relevant process-control actions, but the file contains no visible confirmation, print/log statement, or explicit warning comment explaining them to the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.