Back to skill

Security audit

NanoBanana PPT Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended to generate AI presentations, but its setup handles API keys unsafely and its environment/install behavior is too broad for automatic approval.

Review before installing. Do not paste API keys into Claude Code prompts; configure them locally or through a secret store, rotate any key copied into chat, restrict provider key permissions, and prefer installing only after the package removes the realistic key example, ships .gitignore/.env.example, narrows .env loading, and pins dependencies in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
API_MANAGEMENT.md:68
Finding

Credential-Shaped Google API Key Embedded in Documentation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SECURITY.md:25
Finding

Documented .env Protection Is Absent from the Distributed Project

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
generate_ppt.py:39
Finding

Overbroad Ancestor .env Discovery Can Override Trusted Environment Variables

Content
View full analysis
bool: current_dir = Path(__file__).parent env_locations = [ current_dir / ".env", *[parent / ".env" for parent in current_dir.parents], Path.home() / ".claude" / "skills" / "ppt-generator" / ".env", ] for env_path in env_locations: if env_path.exists(): load_dotenv(env_path, override=True) print(f"Loaded environment from: {env_path}") return True if env_path.parent != current_dir and (env_path.parent / ".git").exists(): break load_dotenv(override=True) print("Warning: No .env file found, using system environment variables") return False ``` ### Technical Analysis The code builds the complete list of parent directories before checking for a project boundary. Depending on installation location, this can include unrelated directories and the user’s home directory. When a discovered file is loaded, `override=True` replaces variables already supplied by the parent process. This contradicts the safer expectation that explicitly configured process environment variables take precedence over local convenience files. The fallback `load_dotenv(override=True)` also performs implicit `.env` discovery based on the library’s default behavior. Therefore, configuration can be loaded from a location not explicitly selected by the user. The Skill only requires its own Gemini credential configuration. Reading arbitrary ancestor `.env` files exceeds that minimum requirement and can import unrelated secrets into the process environment. ### Attack Path 1. An attacker or lower-trust collaborator gains write access to an ancestor directory searched by the Skill. 2. The attacker places a crafted `.env` file in tha ...[truncated 1169 chars]
Remediation
View remediation
bool: selected = env_file or (Path(__file__).resolve().parent / ".env") if not selected.is_file(): print("No Skill .env file found; using inherited environment variables") return False load_dotenv(selected, override=False) print(f"Loaded Skill configuration from: {selected}") return True ``` 7. If ancestor discovery must be retained, identify a canonical project root first and never search above it. 8. Document the exact precedence order and ensure implementation matches that order. ]]>

T08 · Insecure Dependencies

Warning
Location
install_as_skill.sh:116
Finding

Installer Resolves Unpinned Dependencies into the Active Python Environment

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (166)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document includes what appears to be a real hardcoded API key in a section explicitly labeled as an insecure example. Even if intended for demonstration, publishing a realistic or active credential in documentation can lead to unauthorized API use, billing abuse, and possible downstream compromise if the key remains valid.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 115)May include surrounding context.

bash
# 开发环境
.env.development

# 测试环境
.env.test

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 128)May include surrounding context.

bash
# 开发环境
.env.development

# 测试环境
.env.test

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 131)May include surrounding context.

bash
# 开发环境
.env.development

# 测试环境
.env.test

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 121)May include surrounding context.

.env.test

生产环境

.env.production

text

使用时指定:

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · ENV_SETUP.md (reported line 111)May include surrounding context.

PI密钥

text

### 在其他机器上使用

当您在新机器上克隆项目时:

**步骤1**: 克隆仓库
```bash
git clone https://github.com/你的用户名/ppt-generator.git
cd ppt-generator

步骤2: 配置环境变量(根据Shell选择)

zsh用户(推荐):

bash
echo 'export GEMINI_API_KEY="your-api-key"' >> ~/.zshrc
source ~/.zshrc

bash用户:

bash
echo 'export GEMINI_API_KEY="your-api-key"' >> ~/.bashrc
source ~/.bashrc

fish用户:

bash
set -Ux GEMINI_API_KEY "your-api-key"

步骤3: 安装依赖并运行

bash
python3 -m venv venv
source venv/bin/activate
pip install google-genai pillow
./run.sh --help

🔄 管理API密钥

查看当前密钥

bash
echo $GEMINI_API_KEY

临时修改密钥(当前会话)

bash
export GEMINI_API_KEY="new-key-here"

永久修改密钥

编辑配置文件:

bash
nano ~/.zshrc  # 或使用你喜欢的编辑器

找到这一行并修改:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The README explicitly instructs users to paste real API keys into a prompt sent to Claude Code. That exposes secrets to the AI tool and potentially to logs, transcripts, extensions, or downstream integrations, violating the principle that credentials should be entered only into local secret stores or environment files. In the context of an agent skill, asking users to hand secrets to the agent materially increases credential-exposure risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This is the same core issue as SQP-2: the README asks users to disclose real API keys to Claude Code during installation. Secrets submitted in prompts may be retained in conversation history or exposed to tooling layers, making credential theft or misuse possible. The danger is amplified because users are told this is the recommended path.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 110)May include surrounding context.

md
pip install google-genai pillow python-dotenv

4. 配置 API 密钥 - 创建 .env 文件:
   cp .env.example .env

5. 编辑 .env 文件,填入我的 API 密钥:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 185)May include surrounding context.

md
pip install google-genai pillow python-dotenv

4. 配置 API 密钥 - 创建 .env 文件:
   cp .env.example .env

5. 编辑 .env 文件,填入我的 API 密钥:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 250)May include surrounding context.

md
pip install google-genai pillow python-dotenv

4. 配置 API 密钥 - 创建 .env 文件:
   cp .env.example .env

5. 编辑 .env 文件,填入我的 API 密钥:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 299)May include surrounding context.

md
pip install google-genai pillow python-dotenv

4. 配置 API 密钥 - 创建 .env 文件:
   cp .env.example .env

5. 编辑 .env 文件,填入我的 API 密钥:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 742)May include surrounding context.

md
pip install google-genai pillow python-dotenv

4. 配置 API 密钥 - 创建 .env 文件:
   cp .env.example .env

5. 编辑 .env 文件,填入我的 API 密钥:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 175)May include surrounding context.

md
pip install google-genai pillow python-dotenv

4. 配置 API 密钥 - 创建 .env 文件:
   cp .env.example .env

5. 编辑 .env 文件,填入我的 API 密钥:

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 210)May include surrounding context.

h

Google AI API 密钥(必需)

GEMINI_API_KEY=your_gemini_api_key_here

可灵 AI API 密钥(可选,用于视频转场功能)

KLING_ACCESS_KEY=your_kling_access_key_here KLING_SECRET_KEY=your_kling_secret_key_here

text

**替代方式:系统环境变量**

```bash
# zsh 用户 (macOS 默认)
echo 'export GEMINI_API_KEY="your-api-key-here"' >> ~/.zshrc
source ~/.zshrc

# bash 用户
echo 'export GEMINI_API_KEY="your-api-key-here"' >> ~/.bashrc
source ~/.bashrc

5. 验证安装

bash
python3 generate_ppt.py --help

应该显示帮助信息,表示安装成功。


🎯 作为 Claude Code Skill 使用

NanoBanana PPT Skills 完全支持 Claude Code Skill 标准,可以直接通过 Claude Code 调用。

快速安装为 Skill

方法一:Claude Code 自动安装为 Skill(最简单)

只需复制以下提示词,发送给 Claude Code,它会自动完成 Skill 安装!

text
请帮我将 NanoBanana PPT Skills 安装为 Claude Code Sk

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill-install workflow repeats the same unsafe pattern by telling users to provide real API keys inside a Claude Code installation prompt. This creates unnecessary disclosure of long-lived credentials to the assistant during installation, which is especially risky because the prompt is framed as a recommended setup path. Because this is a skill intended to run inside an agent ecosystem, the unsafe handling of secrets is more dangerous than a normal README example.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Claude Code skill-install example again requests real credentials in-chat, directly exposing sensitive tokens to the AI assistant. This can enable unauthorized API usage, billing abuse, and leakage through chat history or telemetry. In a skill README, this is a substantive security flaw, not just poor wording.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 316)May include surrounding context.

bash
# 在 Skill 目录下创建 .env 文件
cat > ~/.claude/skills/ppt-generator/.env << EOF
# Google AI API 密钥(必需)
GEMINI_API_KEY=your_gemini_api_key_here

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 10)May include surrounding context.

以下敏感文件和目录已被正确忽略,不会被提交到GitHub:

text
✓ .env                  # API密钥配置文件
✓ venv/                 # Python虚拟环境
✓ outputs/              # 生成的PPT图片
✓ *.key, *.pem          # 其他密钥文件

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 30)May include surrounding context.

以下敏感文件和目录已被正确忽略,不会被提交到GitHub:

text
✓ .env                  # API密钥配置文件
✓ venv/                 # Python虚拟环境
✓ outputs/              # 生成的PPT图片
✓ *.key, *.pem          # 其他密钥文件

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 43)May include surrounding context.

以下敏感文件和目录已被正确忽略,不会被提交到GitHub:

text
✓ .env                  # API密钥配置文件
✓ venv/                 # Python虚拟环境
✓ outputs/              # 生成的PPT图片
✓ *.key, *.pem          # 其他密钥文件

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 46)May include surrounding context.

以下敏感文件和目录已被正确忽略,不会被提交到GitHub:

text
✓ .env                  # API密钥配置文件
✓ venv/                 # Python虚拟环境
✓ outputs/              # 生成的PPT图片
✓ *.key, *.pem          # 其他密钥文件

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 99)May include surrounding context.

以下敏感文件和目录已被正确忽略,不会被提交到GitHub:

text
✓ .env                  # API密钥配置文件
✓ venv/                 # Python虚拟环境
✓ outputs/              # 生成的PPT图片
✓ *.key, *.pem          # 其他密钥文件

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 106)May include surrounding context.

以下敏感文件和目录已被正确忽略,不会被提交到GitHub:

text
✓ .env                  # API密钥配置文件
✓ venv/                 # Python虚拟环境
✓ outputs/              # 生成的PPT图片
✓ *.key, *.pem          # 其他密钥文件

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_MANAGEMENT.md (reported line 128)May include surrounding context.

以下敏感文件和目录已被正确忽略,不会被提交到GitHub:

text
✓ .env                  # API密钥配置文件
✓ venv/                 # Python虚拟环境
✓ outputs/              # 生成的PPT图片
✓ *.key, *.pem          # 其他密钥文件

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
API_MANAGEMENT.md:64