Back to skill

Security audit

Doc2slides

Security checks for vulnerabilities and agentic risk

Overview

This document-to-slides skill is mostly purpose-aligned, but it needs review because it can send document contents to configured AI services despite local-only claims and renders generated HTML with weak browser isolation.

Review this before installing if you process confidential documents. Use it only when you are comfortable with document excerpts and API credentials being sent to whichever LLM provider or custom endpoint is configured, or verify a true offline mode first. Run setup in an isolated environment rather than a privileged or shared global Python install, and avoid rendering untrusted generated HTML outside a contained environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/analyze_content.py:117
Finding

Implicit Remote Disclosure of Document Content Through Automatically Selected LLM Provider

Content
View full analysis
dict: """Use LLM to analyze content and generate slide structure.""" if not HAS_LLM: print("Error: LLM adapter not available") return None adapter = LLMAdapter(model=model) # Build prompt with optional user instruction prompt = ANALYZE_PROMPT.format(content=content[:50000]) # Limit content length if instruction: prompt += f""" --- ## 【用户自定义指令 — 最高优先级】 以下用户指令**覆盖**上述所有默认规则,必须严格遵守: {instruction} """ print(f"Analyzing content ({len(content)} chars)...") try: response = await adapter.generate( prompt, temperature=0.3, max_tokens=16000, timeout=300.0 # 5 minutes timeout ) ``` ```python # scripts/llm_adapter.py:67-82 def _get_default_model(self) -> str: """Get default model from environment or OpenClaw config.""" # 1. Check environment variable env_model = os.getenv("LLM_MODEL") if env_model: return env_model # 2. Check OpenClaw models.json for first available model models_config = Path.home() / ".openclaw" / "agents" / "main" / "agent" / "models.json" if models_config.exists(): try: with open(models_config, 'r') as f: config = json.load(f) providers = config.get("providers", {}) for provider_name, provider_config in providers.items(): models = provider_config.get("models", []) if models: return models[0].get("id", "glm-4-flash") except: pass ``` ```python ...[truncated 3133 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/llm_generate_html.py:964
Finding

Untrusted Generated HTML Is Rendered With Incomplete Sanitization and Chromium Sandbox Disabled

Content
View full analysis
]*>', "禁止使用
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
setup.sh:39
Finding

Setup Installs Mutable Unpinned Dependencies From the Active Python Package Index

Content
View full analysis
&1 if ! python3 -c "import pptx" 2>/dev/null; then fail "python-pptx install failed" fi info "python-pptx installed" # Try to install playwright for screenshot rendering if python3 -c "import playwright" 2>/dev/null; then info "playwright already installed" else warn "Installing playwright..." pip3 install --quiet playwright 2>&1 || warn "playwright install skipped (optional)" python3 -c "import playwright" 2>/dev/null && info "playwright installed" || warn "playwright not available - will use template mode only" fi ``` ### Technical Analysis The setup script installs `python-pptx`, `requests`, and `playwright` without exact version constraints, hashes, a lock file, or an isolated virtual environment. Resolution therefore depends on the active package index, pip configuration, platform, and package versions available when setup is run. Python package installation may execute build backends or installation-related code with the privileges of the invoking user. An upstream package compromise, compromised configured index, or malicious dependency selected during resolution could consequently execute code during setup. The issue is a supply-chain hardening weakness rather than evidence that the named packages are currently malicious. ### Attack Path 1. The user follows the documented setup procedure and runs `setup.sh`. 2. `pip3` uses the user's currently configured indexes and resolves mutable package versions. 3. A compromised package release, transitive dependency, or hostile configured index supplies attacker-controlled package content. 4. Pip downloads and installs that content without checking project-maintained hashes. 5. Pack ...[truncated 749 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (93)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

This item is dangerous because the skill requests dependency installation and references optional network-capable libraries and API keys while being described mainly as a local document-to-PPT tool. In the context of users handling sensitive files, unclear setup behavior and undisclosed network-capable components can lead to accidental data exposure or execution of unnecessary installation steps with elevated trust.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file-level security comment claims the script is 'LOCAL-ONLY' and makes 'No network requests', but the code clearly invokes an LLM adapter with raw document content. If that adapter uses a remote model, sensitive document data may be transmitted off-device contrary to user expectations and product claims. Misleading security assertions are especially dangerous in a document-processing skill because users may provide confidential business files.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The prompt gives user-supplied natural-language instructions 'highest priority' over all default rules. In an LLM workflow, this weakens safety and data-minimization constraints because a user can request behavior that overrides protections, such as demanding verbatim inclusion of sensitive content or defeating output constraints. In a document-analysis context, unrestricted instruction priority increases prompt-injection and privacy leakage risk.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/color_schemes.py (reported line 256)May include surrounding context.

python
return '\n'.join(new_lines)
    else:
        # 在设计规范部分添加配色方案
        return prompt.replace(
            "## 设计规范",
            f"## 设计规范\n{color_section}"
        )

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/enhanced_prompt_v2.py (reported line 520)May include surrounding context.

python
return '\n'.join(new_lines)
    else:
        # 在设计规范部分添加配色方案
        return prompt.replace(
            "## 设计规范",
            f"## 设计规范\n{color_section}"
        )

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file-level security comment explicitly claims the component is 'LOCAL-ONLY' and makes 'No network requests,' but the code initializes remote clients for OpenAI, Zhipu, and DeepSeek and sends prompts to their APIs. This mismatch can mislead users and reviewers into trusting the skill with sensitive document content that may actually be transmitted off-host.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is marketed as 'local-first,' but this adapter supports multiple external providers and may send document-derived prompts to third parties. In a document-to-slides context, prompts can contain proprietary or personal data, so the discrepancy materially increases the risk of unintended data exfiltration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file header explicitly claims local-only behavior with no network requests or credential access, yet the implementation relies on an LLM adapter and smart matcher that may call remote services. This kind of misleading trust signal can cause operators to run the skill in environments where outbound AI calls or document exfiltration are prohibited, exposing sensitive document contents to unintended external systems.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code gives user-supplied natural-language instructions highest priority over all built-in generation rules, allowing downstream safety constraints to be overridden inside the LLM prompt. In a document-to-HTML pipeline, this can enable prompt injection from untrusted documents or user input to bypass restrictions, produce unsafe HTML/CSS, leak hidden context, or disable intended validation behavior before output is wrapped and saved.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file claims 'LOCAL-ONLY' and 'No network requests' while also accepting URLs and routing them to an external summarization CLI that may fetch or process remote content. That mismatch is dangerous because it can mislead users and reviewers into trusting the skill with sensitive documents under false privacy assumptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file explicitly claims the component is 'LOCAL-ONLY' with 'No network requests', yet later initializes and invokes an LLM adapter to process slide data. This mismatch can cause sensitive document contents to be sent to a model backend unexpectedly, creating a real data-handling and trust-boundary violation for users who rely on local-only guarantees.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: doc2slides
version: 3.8.2
description: "One-click PDF/Word/Markdown to designer-grade PPT. AI auto-layout + 18 slide types + built-in charts. Local-first, free. Use when: user wants to create slides from a document or convert content to PPT."
license: MIT-0
author: lifei68801
metadata:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation section says 'User says any of → activate' and includes generic phrases such as '做个演示文稿' and 'Generate a presentation from...'. These phrases are broad enough to match normal conversational requests without clear scope limits, exclusions, or context constraints, which could cause unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the agent to ask the user a follow-up question only in Chinese: '有特殊要求吗?页数、风格、重点?没有我按默认来。'. This imposes a specific language choice in the skill behavior without offering the user a language option or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.