T08 · Insecure Dependencies
- Location
SKILL.md:247- Finding
Unpinned and Globally Installed Third-Party Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This PowerPoint skill mostly does what it says, but its unpinned global package installation instructions are broader and riskier than necessary.
Install only in an isolated project or disposable environment. Prefer local, pinned dependencies instead of the documented global npm installs, and check output paths before generation or template edits to avoid overwriting existing work.
SKILL.md:247Unpinned and Globally Installed Third-Party Dependencies
The manifest advertises very broad trigger terms such as 'presentation', 'slide', and 'deck', which can match common user requests beyond the narrow intent of PPTX file handling. This can cause the skill to activate unexpectedly in unrelated contexts, increasing the chance of unintended file operations or inappropriate delegation to this skill.
The skill instructs the agent to create slide files, compile them, and write a final PPTX to fixed paths, but it does not require confirming with the user before creating or overwriting artifacts. In an agentic environment, this can lead to unintended modification of workspace contents or clobbering existing presentation files if names or directories already exist.
The description embeds a trigger list containing very common terms like 'presentation', 'slide', 'deck', and 'slides', which can cause the skill to activate in many ordinary conversations unrelated to a user explicitly requesting PowerPoint generation. In an agentic environment, overbroad triggering can route user content into file-generation or file-processing workflows unexpectedly, increasing the chance of unintended actions or exposure of sensitive content.
This markdown file instructs the agent to delete slides and remove orphaned files as part of editing an existing presentation. Although operational steps are clear, there is no warning that these actions can permanently remove presentation content if applied incorrectly, which is a user-data-impacting behavior for markdown files.
The document specifies "English font" and "Chinese font" requirements as fixed defaults, including Microsoft YaHei for Chinese, without indicating that users may choose alternatives based on locale or preference. This can constitute a language/locale policy issue because it imposes locale-specific presentation choices without opt-in or justification.
The subagent directive hard-codes "Chinese = Microsoft YaHei, English = Arial" as a must-follow instruction, which enforces language-specific formatting without presenting user choice. Because the policy applies to natural-language locale constraints across all file types, this fixed assignment should be opt-in or clearly justified.
This markdown file includes a natural-language rule that ties Chinese-language content to a specific font choice. Because the policy category covers language or locale constraints and the text does not present this as optional or user-selected, it can be read as forcing a locale-specific default without opt-in.
The XML examples specify lang="en-US" for text runs, which can imply a forced language/locale setting in the generated presentation. The file does not indicate that locale should be chosen based on user content or template context, nor does it justify an English-US-only constraint.
This markdown file includes example code that writes a presentation to disk via pres.writeFile({ fileName: "Presentation.pptx" }), but the surrounding documentation does not warn that running the snippet will create or potentially overwrite a local file. Under the markdown-specific warning rule, user-visible disclosure is expected for behaviors that affect user data or filesystem state.
No suspicious patterns detected.