Back to skill

Security audit

image-ppt

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only PPT-making skill, but it needs review because it downplays external AI data-upload risk and recommends unpinned remote install commands.

Review before installing. Prefer a pinned, trusted installation path rather than the README's unpinned npx command, invoke the skill explicitly, and only use it with documents you are allowed to send to the AI/image-generation services in your environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.en.md:105
Finding

Unpinned Third-Party Package Execution During Recommended Installation

Content
View full analysis

Vulnerability Details

File Location: README.en.md:105 and README.md:108
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

bash
npx skills add https://github.com/helloo1568/image-ppt --skill image-ppt

Technical Analysis

The recommended installation command invokes an unpinned third-party npm package through npx. If the package is not already available locally, npx may retrieve its current published version and execute it immediately. The command does not specify an audited package version or validate the downloaded package using a cryptographic hash.

The referenced GitHub repository is also not pinned to an immutable release tag or commit hash. Therefore, both the installer behavior and the repository content can change after this Skill has been audited. This creates a supply-chain trust boundary in which future installation behavior depends on mutable external resources.

No evidence indicates that the currently documented package or repository is malicious. The vulnerability is the unsafe, mutable dependency-execution pattern.

Attack Path

  1. An attacker compromises the npm account, package publication process, GitHub account, or referenced repository.
  2. The attacker publishes a malicious version of the unpinned skills package or modifies the repository content.
  3. A user follows the recommended installation instructions and runs the documented npx command.
  4. npx downloads and executes the altered installer package.
  5. The installer processes attacker-controlled repository content and may execute malicious actions with the privileges of the user running the command.

Impact Assessment

Successful exploitation could permit arbitrary command execution under the installing user's account. Depending on that account's permissions and the behavior of the compromised installer, an attacker could read or modify user-accessible files, ...[truncated 467 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the npm installer to an exact, reviewed version, for example by using an explicit package version rather than the latest available release.
  2. Pin the GitHub source to an immutable, reviewed commit hash or signed release tag.
  3. Publish and verify cryptographic checksums for downloaded Skill content.
  4. Prefer a download-and-review workflow over direct remote package execution.
  5. Use npm lockfiles and integrity metadata where the installation environment supports them.
  6. Document the expected files and hashes so users can verify the package before enabling the Skill.
  7. Recommend running installation with a non-privileged account in a restricted environment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README recommends npx skills add ... without pinning a specific package version or commit, which introduces a supply-chain risk: the fetched package or transitive dependencies could change over time and execute unexpected code during installation. In this context the command is explicitly presented as a one-liner for users to run in an agent/shell-enabled environment, so compromise of the package source or dependency chain could affect the local machine or agent runtime.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.en.md (reported line 110)May include surrounding context.

md
> Install the `image-ppt` skill for me:
>
> 1. Make sure the local skills directory exists (`~/.claude/skills/` or `~/.codex/skills/`)
> 2. Run `git clone https://github.com/helloo1568/image-ppt.git <skills-dir>/image-ppt`
> 3. Verify `SKILL.md` and `references/prompts.md` exist
> 4. Tell me when done; "make a PPT" will trigger it afterwards

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad natural-language requests such as 'Turn this book into a PPT' and 'Make a class-presentation PPT from this PDF', which can overlap with ordinary user requests and cause the skill to activate unexpectedly. In agent environments, overbroad activation can lead to unintended file access, document processing, or execution of the workflow when the user did not explicitly intend to invoke this installed skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger guidance is broad enough to match ordinary user requests such as 'make this PDF into a class presentation,' which increases the chance the agent will invoke this skill unexpectedly. In an agent environment with shell/file capabilities, overly broad activation can lead to unintended document processing, external model usage, or file generation without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The listed trigger phrases are generic and unconstrained, covering common requests for creating PPTs from source material. In a shared agent context, that makes accidental or premature activation more likely, which is risky because the workflow may read local documents, invoke image-generation services, and create output artifacts based on ambiguous user intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README states that the skill 'will not network or upload data,' but elsewhere instructs users to clone from GitHub and recommends GPT-Image-based generation, which inherently involves external service access in many deployments. This mismatch can cause users to disclose sensitive documents under a false assumption of local-only processing, creating privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs users to read source documents and send their contents to image-generation or external AI tools, but it does not warn that uploaded PDFs, books, reports, or internal materials may contain sensitive or proprietary data. This creates a real privacy and data-governance risk because users may unknowingly disclose confidential content to third-party services during document analysis and slide generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases include very generic terms such as '做PPT' and '生成PPT', which are likely to match ordinary user requests unrelated to this specific skill. That can cause unintended activation or routing, leading the agent to apply this workflow when the user did not explicitly request it; while not directly enabling code execution or data exfiltration, it increases prompt-scope confusion and unsafe autonomy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The file is explicitly an English README and links to a Chinese version, but it does not present the language as a user-selectable preference within the skill behavior itself. Because language-policy findings require natural-language review, this can be read as favoring a specific locale presentation without an explicit opt-in in the content shown here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill metadata description is entirely in Chinese and presents the workflow as '图片PPT' without indicating that other languages are supported or selectable. Under the policy, a skill should not impose a specific language or locale unless it is clearly justified or offers user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest lists triggers but provides no activation constraints, disambiguation guidance, or negative examples, so an orchestrator may invoke the skill in ambiguous contexts. In a prompt-only skill that transforms user materials, this primarily creates misrouting and unintended processing risk rather than direct system compromise, but the self-asserted '安全等级 P2(安全)' note should not be trusted and slightly increases concern because it attempts to pre-frame security assessment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains natural-language instructions exclusively in Chinese, including all prompt templates and usage guidance. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy concern when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.