T09 · Insecure Skill Coding Practices
- Location
pptx/scripts/fill-template.js:75- Finding
Unrestricted Image URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This presentation skill has a coherent purpose, but its conversion pipeline can read arbitrary local files, fetch arbitrary URLs, and execute unsanitized rich text in Chromium when slide content is influenced by a user or prompt.
Review before installing, especially if presentations may be generated from untrusted prompts, imported slide JSON, web content, or shared documents. Run it in a restricted workspace with no sensitive files, disable or tightly control outbound network access, avoid arbitrary local image paths, and update the dependency stack before use.
pptx/scripts/fill-template.js:75Unrestricted Image URL Fetching Enables Server-Side Request Forgery
pptx/scripts/fill-template.js:60Image Slots Permit Arbitrary Local File Reads
pptx/scripts/fill-template.js:133Unsanitized Rich-Text Slots Execute Active HTML in Headless Chromium
basic-ftp appears as a transitive dependency under get-uri/pac-proxy-agent/proxy-agent used by Puppeteer browser download and proxy resolution. The package has serious advisories, but in this skill it is likely only reachable if FTP-based proxy/PAC or URI handling is allowed during browser acquisition/network operations, making it less directly exposed than an app that explicitly handles attacker-controlled FTP paths.
The skill description promises automatic template matching and direct editable PPTX generation, but the documented behavior also includes remote image retrieval and intermediate HTML generation, creating a mismatch between user expectations and actual operations. Such misrepresentation is risky because users may approve execution believing it is a local content-generation workflow when it can perform undeclared network activity and filesystem writes.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
3v1PiPWNIWeVPbJXEdpI4Sy+2ZsypqxL2RMBcIE7wKtNl5w0k3S9Jt4Za+bTe8mCI6di0DuZiLk36Gcn8wpgo25Bvm4Sdg5oseXr9UryEds2rPo2sJ2YiTWv0tM6VHi4YcTnLv//7n7GT8CmG4YRjRR32QOIAACAASURBVC06pfzeqIT/BvWn46XnlI+gKyvcECrh//v3f8fO1Zc0U7ieRmCL8k8aDoYeBcbnMa/6bAwjDOTyisdKwvbuu+7Hz1/dl9/Aw1QPHqKRFYYiID+hLVca9C2uFmR6YZa+687OvpNPZL7UqdWAhDTU6kaUJd2Bl/VdQjcYVM9C+SE7fPEIZp4xwJRl0HwsG6C8zvKRNj9biGe2DAxd3qnE5/PUIcLWieyCFvUn4de7NeIPSPyuG2fy6IIbi8++dZ/GDit8OvPysN8wy9k2e/WI5aCWf5TXdUnT1cUl7YU9ONiDwqp0pvLybI6YyeW/cIeDlkNpVwK0rFJ9LdI7OrC+Gro///qrOxrlaP8g90uPP4tPMp3Si1IKE5DLleSLDId6oW0f+3vx2nuNTFb6tO1A24Qkv/g+zXhFesMneaLI7Gbwy75/cEDb7njvdHzPaWv5nfgUD1ca+iufy/iZ/iyCvl1fXdBWurvHJ1qB45UgnV6JUO9zOpwSWkYgbpgMon3sJ8dxYK7lWEPWTUbvIq8jWWf6mQyHjjTqADYOK0h5msEzjUwr8bGUh/BOyaFTTyXCDD1fWMQrBrZdte2VHb6Oop0Z1nEbIXiDT3mTrIT1zG6HpI2XvzfE1L7TXvWldz/GXKTViHB7a9pjrfVd/9aQz/lG2Tp0/Wn+6Oc5WunH9m+akWf6exlvOj/HtrcmN1Z7+hqwHSv7wtyfynUw0Wfzp6Sf269EtPfdgtWeSTR7o7KzwsDewp13YSnw4jL5zd2EMKBV+ZtCpofZPww8DkbaMIur87LKpY2gNJJe2JcCyoVGGzOnMNbcgJPhM3jXUty3AJc
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
3v1PiPWNIWeVPbJXEdpI4Sy+2ZsypqxL2RMBcIE7wKtNl5w0k3S9Jt4Za+bTe8mCI6di0DuZiLk36Gcn8wpgo25Bvm4Sdg5oseXr9UryEds2rPo2sJ2YiTWv0tM6VHi4YcTnLv//7n7GT8CmG4YRjRR32QOIAACAASURBVC06pfzeqIT/BvWn46XnlI+gKyvcECrh//v3f8fO1Zc0U7ieRmCL8k8aDoYeBcbnMa/6bAwjDOTyisdKwvbuu+7Hz1/dl9/Aw1QPHqKRFYYiID+hLVca9C2uFmR6YZa+687OvpNPZL7UqdWAhDTU6kaUJd2Bl/VdQjcYVM9C+SE7fPEIZp4xwJRl0HwsG6C8zvKRNj9biGe2DAxd3qnE5/PUIcLWieyCFvUn4de7NeIPSPyuG2fy6IIbi8++dZ/GDit8OvPysN8wy9k2e/WI5aCWf5TXdUnT1cUl7YU9ONiDwqp0pvLybI6YyeW/cIeDlkNpVwK0rFJ9LdI7OrC+Gro///qrOxrlaP8g90uPP4tPMp3Si1IKE5DLleSLDId6oW0f+3vx2nuNTFb6tO1A24Qkv/g+zXhFesMneaLI7Gbwy75/cEDb7njvdHzPaWv5nfgUD1ca+iufy/iZ/iyCvl1fXdBWurvHJ1qB45UgnV6JUO9zOpwSWkYgbpgMon3sJ8dxYK7lWEPWTUbvIq8jWWf6mQyHjjTqADYOK0h5msEzjUwr8bGUh/BOyaFTTyXCDD1fWMQrBrZdte2VHb6Oop0Z1nEbIXiDT3mTrIT1zG6HpI2XvzfE1L7TXvWldz/GXKTViHB7a9pjrfVd/9aQz/lG2Tp0/Wn+6Oc5WunH9m+akWf6exlvOj/HtrcmN1Z7+hqwHSv7wtyfynUw0Wfzp6Sf269EtPfdgtWeSTR7o7KzwsDewp13YSnw4jL5zd2EMKBV+ZtCpofZPww8DkbaMIur87LKpY2gNJJe2JcCyoVGGzOnMNbcgJPhM3jXUty3AJc
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
3v1PiPWNIWeVPbJXEdpI4Sy+2ZsypqxL2RMBcIE7wKtNl5w0k3S9Jt4Za+bTe8mCI6di0DuZiLk36Gcn8wpgo25Bvm4Sdg5oseXr9UryEds2rPo2sJ2YiTWv0tM6VHi4YcTnLv//7n7GT8CmG4YRjRR32QOIAACAASURBVC06pfzeqIT/BvWn46XnlI+gKyvcECrh//v3f8fO1Zc0U7ieRmCL8k8aDoYeBcbnMa/6bAwjDOTyisdKwvbuu+7Hz1/dl9/Aw1QPHqKRFYYiID+hLVca9C2uFmR6YZa+687OvpNPZL7UqdWAhDTU6kaUJd2Bl/VdQjcYVM9C+SE7fPEIZp4xwJRl0HwsG6C8zvKRNj9biGe2DAxd3qnE5/PUIcLWieyCFvUn4de7NeIPSPyuG2fy6IIbi8++dZ/GDit8OvPysN8wy9k2e/WI5aCWf5TXdUnT1cUl7YU9ONiDwqp0pvLybI6YyeW/cIeDlkNpVwK0rFJ9LdI7OrC+Gro///qrOxrlaP8g90uPP4tPMp3Si1IKE5DLleSLDId6oW0f+3vx2nuNTFb6tO1A24Qkv/g+zXhFesMneaLI7Gbwy75/cEDb7njvdHzPaWv5nfgUD1ca+iufy/iZ/iyCvl1fXdBWurvHJ1qB45UgnV6JUO9zOpwSWkYgbpgMon3sJ8dxYK7lWEPWTUbvIq8jWWf6mQyHjjTqADYOK0h5msEzjUwr8bGUh/BOyaFTTyXCDD1fWMQrBrZdte2VHb6Oop0Z1nEbIXiDT3mTrIT1zG6HpI2XvzfE1L7TXvWldz/GXKTViHB7a9pjrfVd/9aQz/lG2Tp0/Wn+6Oc5WunH9m+akWf6exlvOj/HtrcmN1Z7+hqwHSv7wtyfynUw0Wfzp6Sf269EtPfdgtWeSTR7o7KzwsDewp13YSnw4jL5zd2EMKBV+ZtCpofZPww8DkbaMIur87LKpY2gNJJe2JcCyoVGGzOnMNbcgJPhM3jXUty3AJc
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
3v1PiPWNIWeVPbJXEdpI4Sy+2ZsypqxL2RMBcIE7wKtNl5w0k3S9Jt4Za+bTe8mCI6di0DuZiLk36Gcn8wpgo25Bvm4Sdg5oseXr9UryEds2rPo2sJ2YiTWv0tM6VHi4YcTnLv//7n7GT8CmG4YRjRR32QOIAACAASURBVC06pfzeqIT/BvWn46XnlI+gKyvcECrh//v3f8fO1Zc0U7ieRmCL8k8aDoYeBcbnMa/6bAwjDOTyisdKwvbuu+7Hz1/dl9/Aw1QPHqKRFYYiID+hLVca9C2uFmR6YZa+687OvpNPZL7UqdWAhDTU6kaUJd2Bl/VdQjcYVM9C+SE7fPEIZp4xwJRl0HwsG6C8zvKRNj9biGe2DAxd3qnE5/PUIcLWieyCFvUn4de7NeIPSPyuG2fy6IIbi8++dZ/GDit8OvPysN8wy9k2e/WI5aCWf5TXdUnT1cUl7YU9ONiDwqp0pvLybI6YyeW/cIeDlkNpVwK0rFJ9LdI7OrC+Gro///qrOxrlaP8g90uPP4tPMp3Si1IKE5DLleSLDId6oW0f+3vx2nuNTFb6tO1A24Qkv/g+zXhFesMneaLI7Gbwy75/cEDb7njvdHzPaWv5nfgUD1ca+iufy/iZ/iyCvl1fXdBWurvHJ1qB45UgnV6JUO9zOpwSWkYgbpgMon3sJ8dxYK7lWEPWTUbvIq8jWWf6mQyHjjTqADYOK0h5msEzjUwr8bGUh/BOyaFTTyXCDD1fWMQrBrZdte2VHb6Oop0Z1nEbIXiDT3mTrIT1zG6HpI2XvzfE1L7TXvWldz/GXKTViHB7a9pjrfVd/9aQz/lG2Tp0/Wn+6Oc5WunH9m+akWf6exlvOj/HtrcmN1Z7+hqwHSv7wtyfynUw0Wfzp6Sf269EtPfdgtWeSTR7o7KzwsDewp13YSnw4jL5zd2EMKBV+ZtCpofZPww8DkbaMIur87LKpY2gNJJe2JcCyoVGGzOnMNbcgJPhM3jXUty3AJc
@xmldom/xmldom is present as a transitive dependency via fonteditor-core, and the listed issues include XML serialization/injection and recursion-based denial of service. In a PPT generation skill that may process or emit XML-based Office content, malformed or attacker-influenced XML/font data could plausibly trigger document corruption or service-side DoS, though direct exploitability depends on whether untrusted XML reaches this library.
extract-zip is used by @puppeteer/browsers to unpack browser archives, and the cited symlink arbitrary-write/path traversal issues can be dangerous during installation or browser download. If an attacker can influence the downloaded archive, mirror, cache, or install environment, this could lead to file overwrite outside the intended extraction directory.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
image-size is used by pptxgenjs and parses image metadata; the advisories are infinite-loop DoS issues in specific image parsers. A presentation generator is likely to ingest user-supplied images, so crafted JXL/HEIF/ICNS files could hang the process or exhaust resources during presentation creation.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
js-yaml is included via cosmiconfig used by Puppeteer, and the advisory is CPU-consumption DoS on malicious YAML input. In this skill it is likely only used for configuration loading, so risk depends on whether attackers can supply config files or influence the working directory; absent that, exposure is limited but still real in shared or untrusted environments.
ws is used by jsdom and Puppeteer/Puppeteer-core, and the listed advisories include memory disclosure and fragmentation-based memory exhaustion. Because this skill uses headless browser automation, WebSocket transport is part of the control plane; a reachable malicious endpoint or compromised browser channel could potentially trigger denial of service or leak process memory.
The skill explicitly instructs use of web_search and acceptance of remote image URLs, which introduces network-capable behavior, but it declares no corresponding tool scope or permission boundary. This is dangerous because an agent may make external requests without clear user consent or policy enforcement, potentially leaking prompts, topics, or other user-provided content to third parties.
The skill directs use of web_search to obtain images but does not warn users that external network requests may be made based on their topic or slide content. This can expose potentially sensitive user inputs to search providers or third-party image hosts and creates an unexpected data egress channel.
The README advertises automatic image generation or search but does not disclose that the skill may contact external services or transmit user-provided topic data, prompts, or generated content off-host. In an agent skill context, this omission can lead users to unknowingly expose sensitive project information or trigger unintended network access, making the behavior materially risky even though it is documented as a feature.
The skill explicitly instructs the agent to generate or fetch real images from the web and save them locally, but the user-facing description does not disclose that network retrieval and local file creation may occur. This can lead to unexpected external requests, privacy issues if user topics are sent to third-party services, and surprise persistence of downloaded/generated content on disk.
The script accepts arbitrary local file paths from slide data, resolves them against the current working directory, and reads the file into a data URL with no path restrictions. In a skill setting where slide JSON may be influenced by untrusted input, this can exfiltrate sensitive local files by embedding their contents into generated HTML output.
The script fetches arbitrary HTTP(S) URLs found in slide or template image sources and inlines the response as a data URL. In an agent/skill context, this creates an SSRF/privacy risk because attacker-controlled slide content can trigger outbound network requests, leak IP/environment metadata, and access internal services reachable from the host.
Remote image fetching occurs automatically for any HTTP(S) image source in the document without explicit disclosure or approval. In this presentation-generation skill, that is more dangerous because templated content may be LLM- or user-derived, enabling covert outbound requests, tracking, SSRF, and non-deterministic builds.
The header comment and usage description are written in Chinese only, which imposes a specific language on users and agents without any indication of locale selection or opt-in. This matches the policy category for language or locale constraints expressed in natural language.
The subtitle placeholder explicitly instructs that if the title is Chinese, the subtitle must be the English translation, which encodes a language policy into the template content. This constrains language behavior without offering user choice or documenting that the template is intended only for a specific bilingual context.
The HTML document sets lang="zh-CN", which hard-codes a specific language/locale for the template. This is a natural-language policy concern because the file content itself is largely English and there is no indication that users can opt into or change the locale, nor that the template is intended only for a China-specific context.
The HTML root sets lang="zh-CN", which imposes a specific language/locale on the template. The file also contains mixed guidance text in English and Chinese, but does not provide any user opt-in, alternative locale handling, or justification that this template is intentionally region-specific.
The HTML root sets lang="zh-CN", which imposes a specific language/locale on the template. The file does not provide any user opt-in, alternative locale handling, or explanation that this template is intentionally region-specific.
Detected: suspicious.dangerous_exec