Back to skill

Security audit

Slidev Maker

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Slidev helper skill whose risky items are normal, user-directed presentation and package-management features rather than hidden behavior.

Install is reasonable for Slidev work, but treat generated commands as things to approve consciously: pin dependencies where possible, prefer trusted themes/addons, avoid putting secrets in diagrams or remote assets, use local PlantUML/fonts for sensitive decks, and enable remote control or recording only on trusted networks with deliberate privacy controls.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
rules/themes.md:27
Finding

Unpinned Packages and Arbitrary Theme Sources Enable Supply-Chain Compromise

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15; rules/getting-started.md:13-23, 120; rules/themes.md:27-37; rules/export.md:163
Vulnerability Type: Unpinned and insufficiently verified third-party dependencies
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:15:

bash
pnpm create slidev      # scaffold a new deck (also: npm init slidev)

rules/getting-started.md:13-23:

bash
# pnpm (recommended)
pnpm create slidev

# npm
npm init slidev

# yarn
yarn create slidev

# bun
bun create slidev

rules/getting-started.md:120:

bash
pnpm add slidev-theme-seriph   # optional; installed on first run too

rules/themes.md:27-37:

yaml
---
theme: slidev-theme-geist
---
yaml
---
theme: user/repo
---

rules/export.md:163:

yaml
- run: npm install

Technical Analysis

The Skill recommends executing package-manager scaffolding and installation commands without pinning exact package versions or requiring integrity verification. It also permits themes to be loaded from arbitrary community npm package names and GitHub repository shorthand.

Package-manager commands such as pnpm create slidev, npm init slidev, and pnpm add slidev-theme-seriph resolve mutable package releases at execution time. Consequently, the code executed by a future user can differ from the code available when this Skill was audited. Installation and build processes may execute package lifecycle scripts, build plugins, theme modules, and their transitive dependencies with the privileges of the developer or CI runner.

The theme: user/repo pattern expands the trust boundary further by allowing a repository outside a verified package scope to become an executable build dependency. A malicious, compromised, or incorrectly named repository could supply arbitrary JavaScript executed during dependency installation, Slidev startup, or pres ...[truncated 2583 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin scaffolding and installed packages to reviewed exact versions:

    bash
    pnpm create slidev@REVIEWED_VERSION
    pnpm add --save-exact slidev-theme-seriph@REVIEWED_VERSION
    
  2. Commit the package-manager lockfile and enforce it in local and CI builds:

    bash
    npm ci
    

    or:

    bash
    pnpm install --frozen-lockfile
    
  3. Replace the GitHub Actions npm install instruction with npm ci, and fail the workflow if the lockfile is missing or inconsistent.

  4. Restrict automatic recommendations to verified official Slidev package scopes and explicitly reviewed repositories. Warn users that community themes and addons execute code during installation or build.

  5. Avoid recommending arbitrary theme: user/repo sources. If repository-based themes are necessary, pin them to a reviewed immutable commit rather than a mutable branch or repository default.

  6. Verify package ownership, package name, release provenance, integrity metadata, and repository identity before installation. Use registry allowlists or an internal package proxy for sensitive environments.

  7. Inspect unfamiliar dependencies before allowing lifecycle scripts. Where operationally practical, perform the initial install with lifecycle scripts disabled and enable them only after review.

  8. Run Slidev installation and builds in an isolated, least-privileged environment without unrelated credentials. Limit CI token permissions and expose deployment secrets only to jobs that require them.

  9. Add automated dependency scanning, lockfile review, provenance verification, and alerts for maintainer or repository changes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · rules/animations.md (reported line 9)May include surrounding context.

Make elements appear on click.

html
<!-- Component usage -->
<v-click>This appears after one click</v-click>

<!-- Directive usage -->

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · rules/troubleshooting.md (reported line 9)May include surrounding context.

If a build fails, clear the Vite cache and rebuild:

bash
rm -rf node_modules/.vite
slidev build

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The text says remote URLs can be used directly, but the example prefixes the remote URL with /, producing a root-relative local path rather than a direct remote URL. This is an active contradiction between the documentation's stated intent and the shown usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This documentation explicitly teaches use of monaco-run, which executes code in the browser, but it does not clearly warn users that embedded examples can run arbitrary JavaScript with side effects in the presentation environment. In a skill used to create Slidev content, this increases the chance that users copy executable snippets into decks or open untrusted decks without understanding that code execution may occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states that Slidev uses the public PlantUML server by default but does not warn users that diagram source content is transmitted to a third-party external service for rendering. This can expose confidential architecture, credentials accidentally embedded in diagrams, internal hostnames, or other sensitive metadata, especially in enterprise or private presentation workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs users to enable remote access to the presentation on the local network, including an option to set a password inline, but gives no warning that this exposes the presenter interface and slide controls to other reachable devices. In the context of presenter mode, this can leak speaker notes, allow unauthorized slide control, and encourage weak shared-secret practices if users copy the example without understanding the exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The recording section describes screen and camera capture as a simple built-in feature without warning that recordings may capture sensitive on-screen content, microphone/camera data, notifications, or bystanders. In a presentation workflow, users may expose private notes, internal slides, or personal data if they enable recording without understanding the privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The guidance encourages use of remote assets and mentions automatic caching without warning that rendering the presentation may contact third-party servers. In a presentation-building skill, this can cause unintended external requests, leaking IP address, user agent, referrer/project context, and potentially exposing sensitive usage patterns when users include untrusted remote resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file instructs users to embed external URLs in iframe layouts, including examples pointing to third-party sites, but it does not mention any privacy, tracking, or external-content implications. For markdown files, SQP-2 applies when potentially privacy-affecting behavior is described without warnings.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.