Back to skill

Security audit

QoderWork PPT (Jack)

Security checks for vulnerabilities and agentic risk

Overview

This presentation skill has a coherent purpose, but its conversion pipeline can read arbitrary local files, fetch arbitrary URLs, and execute unsanitized rich text in Chromium when slide content is influenced by a user or prompt.

Review before installing, especially if presentations may be generated from untrusted prompts, imported slide JSON, web content, or shared documents. Run it in a restricted workspace with no sensitive files, disable or tightly control outbound network access, avoid arbitrary local image paths, and update the dependency stack before use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
pptx/scripts/fill-template.js:75
Finding

Unrestricted Image URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
pptx/scripts/fill-template.js:60
Finding

Image Slots Permit Arbitrary Local File Reads

Content
View full analysis
Remediation
View remediation
/output/images`. 2. Reject absolute paths and any input containing traversal components. 3. Resolve both the approved root and requested file with `realpath`. 4. Verify that the canonical requested path is a descendant of the canonical approved root using a separator-aware comparison. 5. Reject symbolic links or ensure their canonical targets remain within the approved root. 6. Use `stat` to require a regular file. 7. Enforce a conservative maximum file size before reading. 8. Validate the actual file signature and allow only required formats such as PNG, JPEG, GIF, or WebP. 9. Derive the MIME type from verified file content rather than the user-provided extension. 10. Apply the same centralized validation in both `validate-slides.js` and `fill-template.js` so direct invocation of the filler cannot bypass checks. 11. Run the Skill under a dedicated low-privilege account with no access to credentials or unrelated user files. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
pptx/scripts/fill-template.js:133
Finding

Unsanitized Rich-Text Slots Execute Active HTML in Headless Chromium

Content
View full analysis
'); } else { el.textContent = value; } } ``` Rich-text slots are declared in `pptx/templates/manifest.json:12, 70-72, 155`, including cover descriptions, content blocks, and quotes. The generated HTML is subsequently embedded into unsandboxed `srcdoc` iframes at `pptx/scripts/html-to-pptx-dom.js:56-59`: ```js const iframeParts = []; for (let i = 0; i < files.length; i++) { const html = readFileSync(join(inputDir, files[i]), 'utf-8'); iframeParts.push(``); } ``` The container is loaded with normal JavaScript and network capabilities at `pptx/scripts/html-to-pptx-dom.js:84-90`: ```js console.log('Launching browser...'); const browser = await puppeteer.launch({ headless: true }); const page = await browser.newPage(); await page.setViewport({ width: 1920, height: 1080 * files.length }); try { await page.goto(containerUrl, { waitUntil: 'networkidle0', timeout: 30000 }); ``` ### Technical Analysis Values designated as rich text are inserted directly through `innerHTML`. Replacing newlines with `
` does not sanitize HTML. An attacker can supply active markup such as: - Script elements. - Elements with event-handler attributes. - Iframes, objects, or embeds. - SVG with active content. - External images, stylesheets, or other resource-loading elements. - Markup designed to consume excessive CPU or memory. The generated HTML is later loaded inside Chromium. The iframe has no `sandbox` attribute, JavaScript is enabled, and no request interception or Content Security Policy blocks outbound connections ...[truncated 2092 chars]
Remediation
View remediation
` elements between lines. 2. If limited formatting is required, sanitize with a mature HTML sanitizer configured with a strict allowlist. 3. Permit only essential passive formatting tags, such as `br`, `strong`, and `em`. 4. Remove all: - Script elements. - Event-handler attributes. - Iframes, objects, embeds, SVG, MathML, forms, and media elements. - Style attributes unless rigorously filtered. - URLs and resource-loading attributes unless separately validated. 5. Disable JavaScript during rendering with Puppeteer when the exporter does not require it before bundle execution, or isolate exporter execution from slide content. 6. Add a restrictive Content Security Policy to the container and iframe documents. 7. Intercept browser requests and deny all network access during conversion. 8. Add an iframe `sandbox` attribute with only the minimum capabilities required for DOM extraction. 9. Run Chromium in a hardened operating-system sandbox or isolated container with no credentials, private-network access, or sensitive mounted files. 10. Add security tests containing scripts, event handlers, SVG payloads, external resources, and malformed HTML to confirm that active content is removed. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (66)

Known Vulnerable Dependency: basic-ftp==5.1.0 — 4 advisory(ies): CVE-2026-27699 (Basic FTP has Path Traversal Vulnerability in its downloadToDir() method); GHSA-6v7q-wjvx-w8wg (basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Exe); CVE-2026-41324 (basic-ftp vulnerable to denial of service via unbounded memory consumption in Cl) +1 more

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

basic-ftp appears as a transitive dependency under get-uri/pac-proxy-agent/proxy-agent used by Puppeteer browser download and proxy resolution. The package has serious advisories, but in this skill it is likely only reachable if FTP-based proxy/PAC or URI handling is allowed during browser acquisition/network operations, making it less directly exposed than an app that explicitly handles attacker-controlled FTP paths.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description promises automatic template matching and direct editable PPTX generation, but the documented behavior also includes remote image retrieval and intermediate HTML generation, creating a mismatch between user expectations and actual operations. Such misrepresentation is risky because users may approve execution believing it is a local content-generation workflow when it can perform undeclared network activity and filesystem writes.

Content

No source excerpt is available for this finding.

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · pptx/output/filled/slide-03-section-divider.html (reported line 86)May include surrounding context.

html
3v1PiPWNIWeVPbJXEdpI4Sy+2ZsypqxL2RMBcIE7wKtNl5w0k3S9Jt4Za+bTe8mCI6di0DuZiLk36Gcn8wpgo25Bvm4Sdg5oseXr9UryEds2rPo2sJ2YiTWv0tM6VHi4YcTnLv//7n7GT8CmG4YRjRR32QOIAACAASURBVC06pfzeqIT/BvWn46XnlI+gKyvcECrh//v3f8fO1Zc0U7ieRmCL8k8aDoYeBcbnMa/6bAwjDOTyisdKwvbuu+7Hz1/dl9/Aw1QPHqKRFYYiID+hLVca9C2uFmR6YZa+687OvpNPZL7UqdWAhDTU6kaUJd2Bl/VdQjcYVM9C+SE7fPEIZp4xwJRl0HwsG6C8zvKRNj9biGe2DAxd3qnE5/PUIcLWieyCFvUn4de7NeIPSPyuG2fy6IIbi8++dZ/GDit8OvPysN8wy9k2e/WI5aCWf5TXdUnT1cUl7YU9ONiDwqp0pvLybI6YyeW/cIeDlkNpVwK0rFJ9LdI7OrC+Gro///qrOxrlaP8g90uPP4tPMp3Si1IKE5DLleSLDId6oW0f+3vx2nuNTFb6tO1A24Qkv/g+zXhFesMneaLI7Gbwy75/cEDb7njvdHzPaWv5nfgUD1ca+iufy/iZ/iyCvl1fXdBWurvHJ1qB45UgnV6JUO9zOpwSWkYgbpgMon3sJ8dxYK7lWEPWTUbvIq8jWWf6mQyHjjTqADYOK0h5msEzjUwr8bGUh/BOyaFTTyXCDD1fWMQrBrZdte2VHb6Oop0Z1nEbIXiDT3mTrIT1zG6HpI2XvzfE1L7TXvWldz/GXKTViHB7a9pjrfVd/9aQz/lG2Tp0/Wn+6Oc5WunH9m+akWf6exlvOj/HtrcmN1Z7+hqwHSv7wtyfynUw0Wfzp6Sf269EtPfdgtWeSTR7o7KzwsDewp13YSnw4jL5zd2EMKBV+ZtCpofZPww8DkbaMIur87LKpY2gNJJe2JcCyoVGGzOnMNbcgJPhM3jXUty3AJc

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · pptx/output/filled/slide-06-section-divider.html (reported line 86)May include surrounding context.

html
3v1PiPWNIWeVPbJXEdpI4Sy+2ZsypqxL2RMBcIE7wKtNl5w0k3S9Jt4Za+bTe8mCI6di0DuZiLk36Gcn8wpgo25Bvm4Sdg5oseXr9UryEds2rPo2sJ2YiTWv0tM6VHi4YcTnLv//7n7GT8CmG4YRjRR32QOIAACAASURBVC06pfzeqIT/BvWn46XnlI+gKyvcECrh//v3f8fO1Zc0U7ieRmCL8k8aDoYeBcbnMa/6bAwjDOTyisdKwvbuu+7Hz1/dl9/Aw1QPHqKRFYYiID+hLVca9C2uFmR6YZa+687OvpNPZL7UqdWAhDTU6kaUJd2Bl/VdQjcYVM9C+SE7fPEIZp4xwJRl0HwsG6C8zvKRNj9biGe2DAxd3qnE5/PUIcLWieyCFvUn4de7NeIPSPyuG2fy6IIbi8++dZ/GDit8OvPysN8wy9k2e/WI5aCWf5TXdUnT1cUl7YU9ONiDwqp0pvLybI6YyeW/cIeDlkNpVwK0rFJ9LdI7OrC+Gro///qrOxrlaP8g90uPP4tPMp3Si1IKE5DLleSLDId6oW0f+3vx2nuNTFb6tO1A24Qkv/g+zXhFesMneaLI7Gbwy75/cEDb7njvdHzPaWv5nfgUD1ca+iufy/iZ/iyCvl1fXdBWurvHJ1qB45UgnV6JUO9zOpwSWkYgbpgMon3sJ8dxYK7lWEPWTUbvIq8jWWf6mQyHjjTqADYOK0h5msEzjUwr8bGUh/BOyaFTTyXCDD1fWMQrBrZdte2VHb6Oop0Z1nEbIXiDT3mTrIT1zG6HpI2XvzfE1L7TXvWldz/GXKTViHB7a9pjrfVd/9aQz/lG2Tp0/Wn+6Oc5WunH9m+akWf6exlvOj/HtrcmN1Z7+hqwHSv7wtyfynUw0Wfzp6Sf269EtPfdgtWeSTR7o7KzwsDewp13YSnw4jL5zd2EMKBV+ZtCpofZPww8DkbaMIur87LKpY2gNJJe2JcCyoVGGzOnMNbcgJPhM3jXUty3AJc

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · pptx/output/filled/slide-08-section-divider.html (reported line 86)May include surrounding context.

html
3v1PiPWNIWeVPbJXEdpI4Sy+2ZsypqxL2RMBcIE7wKtNl5w0k3S9Jt4Za+bTe8mCI6di0DuZiLk36Gcn8wpgo25Bvm4Sdg5oseXr9UryEds2rPo2sJ2YiTWv0tM6VHi4YcTnLv//7n7GT8CmG4YRjRR32QOIAACAASURBVC06pfzeqIT/BvWn46XnlI+gKyvcECrh//v3f8fO1Zc0U7ieRmCL8k8aDoYeBcbnMa/6bAwjDOTyisdKwvbuu+7Hz1/dl9/Aw1QPHqKRFYYiID+hLVca9C2uFmR6YZa+687OvpNPZL7UqdWAhDTU6kaUJd2Bl/VdQjcYVM9C+SE7fPEIZp4xwJRl0HwsG6C8zvKRNj9biGe2DAxd3qnE5/PUIcLWieyCFvUn4de7NeIPSPyuG2fy6IIbi8++dZ/GDit8OvPysN8wy9k2e/WI5aCWf5TXdUnT1cUl7YU9ONiDwqp0pvLybI6YyeW/cIeDlkNpVwK0rFJ9LdI7OrC+Gro///qrOxrlaP8g90uPP4tPMp3Si1IKE5DLleSLDId6oW0f+3vx2nuNTFb6tO1A24Qkv/g+zXhFesMneaLI7Gbwy75/cEDb7njvdHzPaWv5nfgUD1ca+iufy/iZ/iyCvl1fXdBWurvHJ1qB45UgnV6JUO9zOpwSWkYgbpgMon3sJ8dxYK7lWEPWTUbvIq8jWWf6mQyHjjTqADYOK0h5msEzjUwr8bGUh/BOyaFTTyXCDD1fWMQrBrZdte2VHb6Oop0Z1nEbIXiDT3mTrIT1zG6HpI2XvzfE1L7TXvWldz/GXKTViHB7a9pjrfVd/9aQz/lG2Tp0/Wn+6Oc5WunH9m+akWf6exlvOj/HtrcmN1Z7+hqwHSv7wtyfynUw0Wfzp6Sf269EtPfdgtWeSTR7o7KzwsDewp13YSnw4jL5zd2EMKBV+ZtCpofZPww8DkbaMIur87LKpY2gNJJe2JcCyoVGGzOnMNbcgJPhM3jXUty3AJc

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · pptx/output/filled/slide-10-section-divider.html (reported line 86)May include surrounding context.

html
3v1PiPWNIWeVPbJXEdpI4Sy+2ZsypqxL2RMBcIE7wKtNl5w0k3S9Jt4Za+bTe8mCI6di0DuZiLk36Gcn8wpgo25Bvm4Sdg5oseXr9UryEds2rPo2sJ2YiTWv0tM6VHi4YcTnLv//7n7GT8CmG4YRjRR32QOIAACAASURBVC06pfzeqIT/BvWn46XnlI+gKyvcECrh//v3f8fO1Zc0U7ieRmCL8k8aDoYeBcbnMa/6bAwjDOTyisdKwvbuu+7Hz1/dl9/Aw1QPHqKRFYYiID+hLVca9C2uFmR6YZa+687OvpNPZL7UqdWAhDTU6kaUJd2Bl/VdQjcYVM9C+SE7fPEIZp4xwJRl0HwsG6C8zvKRNj9biGe2DAxd3qnE5/PUIcLWieyCFvUn4de7NeIPSPyuG2fy6IIbi8++dZ/GDit8OvPysN8wy9k2e/WI5aCWf5TXdUnT1cUl7YU9ONiDwqp0pvLybI6YyeW/cIeDlkNpVwK0rFJ9LdI7OrC+Gro///qrOxrlaP8g90uPP4tPMp3Si1IKE5DLleSLDId6oW0f+3vx2nuNTFb6tO1A24Qkv/g+zXhFesMneaLI7Gbwy75/cEDb7njvdHzPaWv5nfgUD1ca+iufy/iZ/iyCvl1fXdBWurvHJ1qB45UgnV6JUO9zOpwSWkYgbpgMon3sJ8dxYK7lWEPWTUbvIq8jWWf6mQyHjjTqADYOK0h5msEzjUwr8bGUh/BOyaFTTyXCDD1fWMQrBrZdte2VHb6Oop0Z1nEbIXiDT3mTrIT1zG6HpI2XvzfE1L7TXvWldz/GXKTViHB7a9pjrfVd/9aQz/lG2Tp0/Wn+6Oc5WunH9m+akWf6exlvOj/HtrcmN1Z7+hqwHSv7wtyfynUw0Wfzp6Sf269EtPfdgtWeSTR7o7KzwsDewp13YSnw4jL5zd2EMKBV+ZtCpofZPww8DkbaMIur87LKpY2gNJJe2JcCyoVGGzOnMNbcgJPhM3jXUty3AJc

Known Vulnerable Dependency: @xmldom/xmldom==0.8.11 — 15 advisory(ies): CVE-2026-83608 (xmldom: DocType `name` Injection Bypasses requireWellFormed); CVE-2026-41673 (xmldom: Uncontrolled recursion in XML serialization leads to DoS); CVE-2026-83605 (xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed) +12 more

High
Category
Supply Chain
Confidence
86% confidence
Finding

@xmldom/xmldom is present as a transitive dependency via fonteditor-core, and the listed issues include XML serialization/injection and recursion-based denial of service. In a PPT generation skill that may process or emit XML-based Office content, malformed or attacker-influenced XML/font data could plausibly trigger document corruption or service-side DoS, though direct exploitability depends on whether untrusted XML reaches this library.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: extract-zip==2.0.1 — 2 advisory(ies): CVE-2026-19693 (extract-zip allows arbitrary file writes through symlink archive entries); CVE-2026-56876 (extract-zip unvalidated symlink path traversal)

High
Category
Supply Chain
Confidence
82% confidence
Finding

extract-zip is used by @puppeteer/browsers to unpack browser archives, and the cited symlink arbitrary-write/path traversal issues can be dangerous during installation or browser download. If an attacker can influence the downloaded archive, mirror, cache, or install environment, this could lead to file overwrite outside the intended extraction directory.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: image-size==1.2.1 — 2 advisory(ies): CVE-2025-71329 (image-size: JXL and HEIF parsers allow denial of service through infinite loops); CVE-2025-71330 (image-size: ICNS parser allows denial of service through an infinite loop)

High
Category
Supply Chain
Confidence
84% confidence
Finding

image-size is used by pptxgenjs and parses image metadata; the advisories are infinite-loop DoS issues in specific image parsers. A presentation generator is likely to ingest user-supplied images, so crafted JXL/HEIF/ICNS files could hang the process or exhaust resources during presentation creation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.1.0 — 2 advisory(ies): CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco); CVE-2026-42338 (ip-address has XSS in Address6 HTML-emitting methods)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

js-yaml is included via cosmiconfig used by Puppeteer, and the advisory is CPU-consumption DoS on malicious YAML input. In this skill it is likely only used for configuration loading, so risk depends on whether attackers can supply config files or influence the working directory; absent that, exposure is limited but still real in shared or untrusted environments.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
80% confidence
Finding

ws is used by jsdom and Puppeteer/Puppeteer-core, and the listed advisories include memory disclosure and fragmentation-based memory exhaustion. Because this skill uses headless browser automation, WebSocket transport is part of the control plane; a reachable malicious endpoint or compromised browser channel could potentially trigger denial of service or leak process memory.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill explicitly instructs use of web_search and acceptance of remote image URLs, which introduces network-capable behavior, but it declares no corresponding tool scope or permission boundary. This is dangerous because an agent may make external requests without clear user consent or policy enforcement, potentially leaking prompts, topics, or other user-provided content to third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs use of web_search to obtain images but does not warn users that external network requests may be made based on their topic or slide content. This can expose potentially sensitive user inputs to search providers or third-party image hosts and creates an unexpected data egress channel.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises automatic image generation or search but does not disclose that the skill may contact external services or transmit user-provided topic data, prompts, or generated content off-host. In an agent skill context, this omission can lead users to unknowingly expose sensitive project information or trigger unintended network access, making the behavior materially risky even though it is documented as a feature.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to generate or fetch real images from the web and save them locally, but the user-facing description does not disclose that network retrieval and local file creation may occur. This can lead to unexpected external requests, privacy issues if user topics are sent to third-party services, and surprise persistence of downloaded/generated content on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script accepts arbitrary local file paths from slide data, resolves them against the current working directory, and reads the file into a data URL with no path restrictions. In a skill setting where slide JSON may be influenced by untrusted input, this can exfiltrate sensitive local files by embedding their contents into generated HTML output.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script fetches arbitrary HTTP(S) URLs found in slide or template image sources and inlines the response as a data URL. In an agent/skill context, this creates an SSRF/privacy risk because attacker-controlled slide content can trigger outbound network requests, leak IP/environment metadata, and access internal services reachable from the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Remote image fetching occurs automatically for any HTTP(S) image source in the document without explicit disclosure or approval. In this presentation-generation skill, that is more dangerous because templated content may be LLM- or user-derived, enabling covert outbound requests, tracking, SSRF, and non-deterministic builds.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The header comment and usage description are written in Chinese only, which imposes a specific language on users and agents without any indication of locale selection or opt-in. This matches the policy category for language or locale constraints expressed in natural language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The subtitle placeholder explicitly instructs that if the title is Chinese, the subtitle must be the English translation, which encodes a language policy into the template content. This constrains language behavior without offering user choice or documenting that the template is intended only for a specific bilingual context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML document sets lang="zh-CN", which hard-codes a specific language/locale for the template. This is a natural-language policy concern because the file content itself is largely English and there is no indication that users can opt into or change the locale, nor that the template is intended only for a China-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The HTML root sets lang="zh-CN", which imposes a specific language/locale on the template. The file also contains mixed guidance text in English and Chinese, but does not provide any user opt-in, alternative locale handling, or justification that this template is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML root sets lang="zh-CN", which imposes a specific language/locale on the template. The file does not provide any user opt-in, alternative locale handling, or explanation that this template is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
pptx/scripts/run-pipeline.js:54