Back to skill

Security audit

Slidev PPT Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Slidev presentation helper, with disclosed local file creation and npm-based setup/export steps, but users should be aware of unpinned npm dependency installs.

Install this only if you are comfortable with it creating or modifying a local Slidev project and running npm installs in that project. For safer use, review the scripts first, run it in a dedicated presentation directory, and consider pinning npm package versions or using a locked template before exporting PDF/PPTX.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/init-project.js:51
Finding

Automatic Installation of Unpinned npm Dependencies

Content
View full analysis

Vulnerability Details

File Location: scripts/init-project.js:51-70, scripts/init-project.js:104-121, and scripts/export.js:51-64, 152-156
Vulnerability Type: Supply-chain exposure through mutable, unpinned npm dependencies
Risk Level: Medium

The project automatically installs third-party packages without specifying exact versions or using a reviewed lockfile. Exporting a presentation can also initiate an installation without a distinct dependency-installation confirmation.

Vulnerable Code

From scripts/init-project.js:51-70:

js
function ensureDeps(projectDir, packages) {
  const pkg = readPackageJson(projectDir);
  const installed = {
    ...(pkg.dependencies || {}),
    ...(pkg.devDependencies || {}),
  };

  const missing = packages.filter((name) => !installed[name]);
  if (missing.length === 0) {
    return;
  }

  console.log(`Installing dependencies: ${missing.join(', ')}`);
  execFileSync('npm', ['i', '-D', ...missing], {
    cwd: projectDir,
    stdio: 'inherit',
  });
}

From scripts/init-project.js:104-121:

js
const baseDeps = ['@slidev/cli'];
const officialThemes = [
  '@slidev/theme-default',
  '@slidev/theme-seriph',
  '@slidev/theme-apple-basic',
  '@slidev/theme-bricks',
  '@slidev/theme-shibainu',
];

ensureDeps(
  projectDir,
  options.installAllOfficialThemes ? [...baseDeps, ...officialThemes] : baseDeps,
);

if (options.withExportDeps) {
  ensureDeps(projectDir, ['playwright-chromium']);
}

From scripts/export.js:51-64:

js
function ensureProjectDep(name) {
  const pkg = JSON.parse(fs.readFileSync('package.json', 'utf8'));
  const installed = {
    ...(pkg.dependencies || {}),
    ...(pkg.devDependencies || {}),
  };

  if (installed[name]) {
    return;
  }

  console.log(`Missing dependency ${name}, installing into project...`);
  execFileSync('npm', ['i', '-D', name], { stdio: 'inhe
...[truncated 2591 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every directly installed dependency to an exact, reviewed version, for example:

    js
    const baseDeps = ['@slidev/cli@<reviewed-version>'];
    

    Apply exact versions to all themes and playwright-chromium.

  2. Provide a maintained project template with a committed package-lock.json, and install it using:

    bash
    npm ci
    

    This ensures package versions and integrity hashes match reviewed dependency state.

  3. Avoid automatically installing dependencies during export. If an export dependency is missing, stop and display the exact proposed package and version, then require explicit user confirmation.

  4. Use --ignore-scripts where lifecycle scripts are not required:

    bash
    npm ci --ignore-scripts
    

    If Playwright requires a browser installation step, perform that step separately and explicitly after validating the package and version.

  5. Validate the npm registry before installation and document the expected trusted registry. Consider enforcing it through a project-local .npmrc.

  6. Add automated dependency review, vulnerability scanning, and lockfile-integrity checks to the release process. Review version updates before changing the pinned dependency set.

  7. Document that initialization and export may access the network and execute third-party installation code so operators can run the process in an appropriately restricted environment.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code is clearly related to Slidev and Markdown slide generation, so the general domain matches the description. However, the declared purpose says the skill can 'Generate and export presentations using Slidev,' including export to PDF/PPTX/HTML. This code only creates a Slidev-compatible slides.md file and saves it locally. It merely prints next-step instructions telling the user to run Slidev manually; it does not invoke Slidev, launch a preview server, or export any output formats. Therefore the description materially overstates the implemented behavior, making this a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · demo/openclaw-intro/slides.md (reported line 642)May include surrounding context.

md
</div>
<div class="text-xs text-gray-500 mt-2">

位置:`~/.openclaw/secrets.json` (权限 600)

</div>

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 15)May include surrounding context.

md
## ✨ Features / 特性

- 🎯 **AI-Powered** - OpenClaw auto-generates content
- 📝 **Markdown Authoring** - Create slides like writing docs
- 🎨 **Multiple Themes** - Built-in + community themes
- 📤 **Multi-format Export** - HTML / PDF / PPTX
- 🔧 **Highly Customizable** - Vue components + custom styles

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to execute npx clawhub@latest install ..., which fetches and runs the latest published package without pinning a specific version. This creates a supply-chain risk: a compromised upstream package or malicious new release could execute arbitrary code during installation on the user's machine.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage guidance tells the agent to act on broad natural-language requests like 'Make a PPT about ...', which overlaps with many ordinary presentation-related prompts. In an agent skill ecosystem, broad invocation language can cause unintended activation, leading the skill to create files, start servers, or install/export tooling when the user did not explicitly intend to use this specific skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs use of npx slidev without pinning a specific package version. npx may fetch and execute the latest published package or resolve an unexpected version from the environment, creating a supply-chain risk where compromised or breaking upstream releases run in the user's context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This export command again relies on unpinned npx slidev, which can download and execute whatever version is current at runtime. In a tool that performs file generation and export, that unnecessarily exposes users to malicious package updates or incompatible behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The PDF export guidance uses npx slidev export without version pinning. Because export may install or run additional browser tooling, executing an unpinned package increases supply-chain exposure and can lead to arbitrary code execution in the local environment if the dependency chain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The troubleshooting step npx slidev --version still triggers package resolution and possible execution of an unpinned package. Even version-check commands can fetch and run remote code, so this remains a real supply-chain risk rather than a harmless diagnostic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file states that openclaw-backup performs daily automatic backups to ~/openclaw-backups/ and retains seven archives, which is a user-data-affecting file operation. The description presents the behavior as a feature but does not warn users that local files and archives will be created on a schedule or discuss storage/privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The cron task list includes MEM Daily Plan, MEM Check-in, MEM Weekly Review, and 周报自动生成, indicating recurring automated behaviors that may generate or process user content. The file does not provide a warning that these automations run on a schedule and may affect user data, records, or workflow unless reviewed and configured first.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script automatically runs npm i -D <name> inside the user's project, which modifies package manifests and fetches code from the package ecosystem during what is presented as an export operation. This expands trust to external registries and install scripts, creating supply-chain and integrity risks that are disproportionate to the stated purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The export wrapper performs side effects beyond exporting by automatically initializing a Slidev project and altering the current working directory when Slidev is missing. In a skill that appears to be a simple export utility, silently creating project files and changing dependencies violates least surprise and can lead to unintended workspace modification or execution of additional setup logic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool modifies the user's project by initializing Slidev and potentially triggering dependency setup without prominently warning about those actions in the primary usage flow. In the context of an agent skill, hidden mutation is especially risky because users may expect a read-mostly export action, not filesystem and dependency changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s descriptive content is primarily written in Chinese, while also showing that user requests may be in either Chinese or English. Under the policy criteria, forcing or assuming a specific language without explicit user opt-in or a documented region-specific justification can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · demo/openclaw-intro/package.json (reported line 3)May include surrounding context.

json
{
  "devDependencies": {
    "@slidev/theme-seriph": "^0.25.0",
    "playwright-chromium": "^1.58.2"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · demo/openclaw-intro/package.json (reported line 4)May include surrounding context.

json
{
  "devDependencies": {
    "@slidev/theme-seriph": "^0.25.0",
    "playwright-chromium": "^1.58.2"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The title and slide content are written entirely in Chinese, and there is no indication that the language is optional, user-selected, or required for a specific regional/compliance context. Under the policy, forcing a specific language without opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description text is written only in Chinese ('使用 Slidev 生成专业演示文稿'), which indicates a fixed language presentation in the skill metadata. Under the policy, language constraints should either offer user choice or be clearly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The inline help presents this script as supporting pdf|pptx|png|md, while the surrounding skill description frames the tool around Slidev presentation generation and PDF/PPTX/HTML export workflows. This creates intent ambiguity in the documentation about what output modes are actually part of the supported purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template uses Chinese for the title, headings, labels, and placeholder text across the entire file. Under the policy rule for natural-language violations, a fixed language choice without opt-in or documented locale justification can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/export.js:96