Back to skill

Security audit

Slide Creator

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a coherent slide-generation skill, but its generated decks can silently send edited presentation content back to the hosting server when saving.

Review this carefully before installing. Avoid editing and saving generated non-Blue-Sky decks from an HTTP/HTTPS origin you do not fully trust, because saving can upload the entire edited deck, including speaker notes, to that origin. The Electron preload file should be removed from the skill package or audited with its main-process handlers before use in any desktop wrapper.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/js-engine.md:226
Finding

Silent Same-Origin Transmission of Complete Presentation Content

Content
View full analysis
\n' + document.documentElement.outerHTML; const bytes = new TextEncoder().encode(html); fetch(location.pathname, { method: 'PUT', body: bytes, headers: { 'Content-Type': 'text/html' } }) .catch(() => { const a = Object.assign(document.createElement('a'), { href: URL.createObjectURL(new Blob([html], { type: 'text/html' })), download: location.pathname.split('/').pop() || 'presentation.html' }); a.click(); URL.revokeObjectURL(a.href); }); } ``` This behavior is propagated into numerous generated demonstrations, including `demos/aurora-mesh-zh.html:675`. ### Technical Analysis The save handler serializes the complete document using `document.documentElement.outerHTML`. This includes edited slide text, speaker notes stored in document attributes, embedded resources, and other presentation metadata. It then issues an HTTP `PUT` request to `location.pathname`. A local Blob download is used only when that network request fails. Consequently, when a presentation is served over HTTP or HTTPS, pressing Ctrl/Cmd+S sends the complete presentation to the server currently hosting the page. The request is same-origin and therefore is not blocked by ordinary cross-origin protections. No confirmation prompt, trusted-origin allowlist, explicit server-save configuration, or indication that presentation data will be transmitted is present in the reviewed implementation. Server-side saving may be a legitimate optional feature, but making it the default exceeds the minimum network privileges required for a browser-based HTML presentation generator. ### Attack Path 1. An attacker or untrusted third party hosts a gen ...[truncated 1296 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
preload.cjs:73
Finding

Unrelated Privileged Electron File-Access Bridge Exposed to Renderer Content

Content
View full analysis
ipcRenderer.invoke('desktop:readFileContent', { filePath }), ``` The same preload bridge also exposes unrelated privileged operations such as model configuration changes, skill and MCP installation, update installation, channel management, reminders, and KSwarm service controls. ### Technical Analysis Electron preload scripts operate at a security boundary between untrusted renderer JavaScript and privileged main-process functionality. This preload exposes a `readFileContent` method accepting a renderer-controlled path and forwards it to the main process through IPC. No corresponding main-process handler is included in the audited project, so path confinement, authorization, symlink handling, and sensitive-file restrictions cannot be verified. If the handler trusts the supplied path, renderer content could request files outside the project or user-selected workspace. This capability is unrelated to the declared slide-generation functionality and therefore violates least-privilege design. Its presence is particularly concerning if the preload is attached to a window that can display remote content, generated HTML, imported presentations, or content affected by HTML injection. The audit did not establish that this preload is loaded by the slide generator itself or that the absent main-process handler performs unrestricted reads. The risk arises from packaging a broad privileged bridge without its security controls or a documented requirement. ### Attack Path 1. An Electron host loads `preload.cjs` for a renderer window. 2. The renderer loads compromised remote content, an attacker-controlled presentation, or content affected by script injection. 3. Malicious renderer JavaScript accesses `window.xiaokDesktop.readFileContent ...[truncated 1221 chars]
Remediation
View remediation
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (445)

Dangerous chain: exec() wrapping compile

Critical
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

A dangerous execution chain combines code execution (exec/eval) with a dynamic source (network, encoded data, dynamic import), creating a high-confidence attack vector.

Content

Scanner excerpt · tests/test_validate_console_output.py (reported line 38)May include surrounding context.

python
source = VALIDATE_PY.read_text(encoding="utf-8")
    namespace = {"__name__": "validate_module_exec"}

    exec(compile(source, str(VALIDATE_PY), "exec"), namespace)

    assert namespace["ROOT"] == ROOT
    assert namespace["SCRIPTS_DIR"] == ROOT / "scripts"

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The file presents the skill as a slide generator, but the behavior described by the findings includes validation, regression testing, local file inspection, subprocess execution, and evaluation/report generation. This kind of capability mismatch is dangerous because users and orchestrators may approve or invoke the skill under a low-risk content-generation mental model while it performs higher-risk repository and execution operations.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/run_evals.py:40

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_audit_style_consistency_autofix.py:13

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_export_integration.py:123

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_family_demo_strict_validate.py:28

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_main_cli.py:19

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_skill_eval_runner.py:32

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_title_profile_registry.py:28

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_validate_console_output.py:15

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_validate_css_vars.py:17

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_validate_default_chrome.py:17

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_validate_js_engine_contract.py:17

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_validate_priority_preset_contracts.py:17

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_validate_title_balance.py:17

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_validate_visual_variety.py:17