Back to skill

Security audit

OnePress Deck

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed slide-deck generator; it writes local HTML decks by default and uses OnePress network APIs when an API key is configured.

Install this if you want an agent to create slide decks. Without ONEPRESS_API_KEY it writes a local HTML file; with the key set, your prompt and follow-ups are sent to OnePress and may remain in its workspace, so avoid secrets, regulated data, or confidential business material unless that is approved for the service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The usage guidance is broad enough that an agent could invoke the skill for ordinary 'make me a deck' requests without the user explicitly choosing this skill or understanding its behavior. In this skill, that matters because activation can lead to local file generation by default and, when configured, network submission of potentially sensitive prompt content to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README describes connected mode as submitting tasks and polling results, but does not clearly warn that the user's deck prompt and related task data are transmitted to OnePress over the network. This can cause unintentional disclosure of confidential business plans, investor materials, sales data, or internal research if users assume the skill operates locally like the default mode.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to send the user's task description to an external OnePress API in connected mode, but it does not require an explicit user-facing notice or consent at the moment data leaves the local environment. Because deck requests may contain sensitive business, financial, or personal information, this creates a real privacy and data-governance risk even if the service is legitimate.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
connected mode delegates to OnePress infrastructure. Never fabricate artifacts
  or links.
- `preview_path` is not downloadable over the API — direct the user to the app.
- Never ask the user to paste their API key into chat; it belongs in env/config only.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example instructs the agent to send a user’s full deck request to an external OnePress API using a bearer token, but it does not disclose that prompt content will leave the local environment. This creates a real privacy and data-handling risk because users may include confidential business strategy, customer data, or other sensitive material in prompts without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The template sets <html lang="en">, which imposes an English locale by default. The file does not say this is optional, user-selectable, or required for a region-specific reason, so it can violate the language/locale policy for users wanting another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file directs the skill to create a file on the user's filesystem, which is a user-data-affecting action. The document does not include a clear warning or disclosure to the user that the skill will write a new file locally before doing so.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.