Back to skill

Security audit

Mck Skill Repo

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent PowerPoint-generation skill with some install-time supply-chain hygiene concerns but no hidden persistence, snooping, exfiltration, or destructive behavior found.

Install in a virtual environment or other low-privilege workspace, pin and review python-pptx/lxml versions before use, and avoid relying on mutable @latest commands when reproducibility matters. Expect the skill to create or modify local PPTX files and to apply a Chinese/English typography style unless you customize it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:143
Finding

Unpinned Third-Party Dependencies and Mutable Package Installation

Content
View full analysis
=0.6.21 lxml>=4.9.0 ``` ### Technical Analysis The installation instructions do not select immutable, previously reviewed package artifacts. The unversioned `pip install` command retrieves whichever compatible releases are current at installation time. The requirements files use lower bounds rather than exact versions, allowing future versions of both packages to be installed without review. The command `npx clawhub@latest` is more explicitly mutable: the `latest` distribution tag can resolve to a different package version after this project has been audited. Package-manager installation and execution therefore place trust in future registry content, publisher accounts, transitive dependencies, and package lifecycle behavior. No evidence shows that the currently named packages are malicious. The vulnerability is the lack of reproducibility and integrity enforcement, which allows the effective code installed or executed by users to change after review. ### Attack Path 1. An attacker compromises a dependency publisher, package registry, release workflow, or transitive dependency. 2. The attacker publishes a malicious release that still satisfies `python-pptx>=0.6.21` or `lxml>=4.9.0`, or changes the package resolved through the `latest` ClawHub ta ...[truncated 1164 chars]
Remediation
View remediation
lxml== ``` 2. Generate and commit a lock file containing all transitive dependencies. 3. Require artifact hashes during installation. For pip, maintain a hash-locked requirements file and install it with: ```bash python -m pip install --require-hashes -r requirements.lock ``` 4. Replace `npx clawhub@latest` with a specific reviewed version: ```bash npx clawhub@ install mck-ppt-design ``` 5. Configure package managers to use explicitly trusted registries and avoid unintended fallback registries. 6. Run dependency installation in an isolated virtual environment or container under a non-privileged account. 7. Add automated dependency scanning and a controlled update process. Review source changes, transitive dependencies, package ownership, and checksums before updating pinned versions. 8. Keep the installation commands in `README.md`, `SKILL.md`, and both requirements files synchronized so that none of the documented paths bypass the hardened dependency policy. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The primary description and much of the README are written entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This creates a natural-language locale policy concern because the documentation effectively imposes a specific language without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The README instructs users to run npx clawhub@latest install mck-ppt-design, which fetches and executes the latest published package version at install time. Because @latest is mutable, a compromised publisher account, malicious release, or breaking upstream change could cause arbitrary code execution on the user's machine during installation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 154)May include surrounding context.

npx clawhub@latest install mck-ppt-design

或手动安装

mkdir -p ~/.claude/skills/mck-ppt-design cp SKILL.md ~/.claude/skills/mck-ppt-design/

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 154)May include surrounding context.

npx clawhub@latest install mck-ppt-design

或手动安装

mkdir -p ~/.claude/skills/mck-ppt-design cp SKILL.md ~/.claude/skills/mck-ppt-design/

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is overly broad and user-invocable, covering many generic presentation requests without tight boundaries. In an agent environment, this can cause unintended activation on loosely related prompts, leading the agent to invoke Bash, Read, and Write in situations where a safer or narrower skill should have been selected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The overview advertises 'Chinese + English font handling' and later the document repeatedly mandates KaiTi for Chinese text as the default behavior. This imposes a locale-specific presentation style without offering the user a language or locale choice, which may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The 'When to Use This Skill' section defines activation conditions broadly and lacks clear non-applicable cases. Because the skill is user-invocable and permitted to use file and shell tools, vague routing criteria increase the chance of unnecessary tool-enabled execution in response to ordinary discussion about slides or presentation strategy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The typography section specifies 'Chinese (ALL): KaiTi' and states that every paragraph with Chinese text MUST apply set_ea_font() using KaiTi. This is a hard locale-specific requirement rather than an optional or justified regional constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The layout description presents each action card as containing timeline, description, and owner. In the sample code, the owner label and dividing line appear after the loop body, so they execute only once using the final loop values rather than once per card, contradicting the described layout behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The version history explicitly states that connector-based lines were replaced and that add_line() is deprecated in favor of add_hline(). However, earlier code templates in the document still call add_line() (for example in the cover slide and table examples), which contradicts the stated guidance and can mislead an agent into using the deprecated approach.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is specified with only a minimum version and no upper bound or exact pin, which makes builds non-reproducible and allows future package releases to be pulled in implicitly. This increases supply-chain risk because a later compromised or breaking release of python-pptx could be installed without review.

Content

Scanner excerpt · examples/requirements.txt (reported line 1)May include surrounding context.

text
python-pptx>=0.6.21
lxml>=4.9.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The lxml dependency is also unpinned, so installations may resolve to different versions over time. In a package with known historical advisories, leaving the version unconstrained makes it harder to verify whether deployments are using a safe release and increases supply-chain exposure.

Content

Scanner excerpt · examples/requirements.txt (reported line 2)May include surrounding context.

text
python-pptx>=0.6.21
lxml>=4.9.0

Unverifiable Dependency: lxml has 14 known advisory(ies) (CVE-2021-43818 (lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through); CVE-2014-3146 (lxml Cross-site Scripting Via Control Characters); CVE-2021-28957 (lxml vulnerable to Cross-Site Scripting ) +11 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest references lxml without an exact version, and lxml has multiple known advisories across some releases. Because the installed version cannot be determined from this file, consumers may inadvertently install an affected version, especially in fresh environments or over time as resolvers change.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is specified with a minimum version only, which allows future installs to resolve to different releases over time. This weakens build reproducibility and can unintentionally introduce vulnerable or incompatible versions through the supply chain.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
python-pptx>=0.6.21
lxml>=4.9.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The lxml dependency is unpinned, so installations may resolve to any later version that satisfies the constraint. Because lxml has a history of security advisories, leaving it floating increases the chance of pulling an affected or unreviewed release and makes it impossible to verify the security posture of deployed environments.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
python-pptx>=0.6.21
lxml>=4.9.0

Unverifiable Dependency: lxml has 14 known advisory(ies) (CVE-2021-43818 (lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through); CVE-2014-3146 (lxml Cross-site Scripting Via Control Characters); CVE-2021-28957 (lxml vulnerable to Cross-Site Scripting ) +11 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The manifest does not pin lxml, so there is no way to determine whether deployed instances use a version affected by known lxml advisories. In a presentation-generation skill, this is somewhat context-dependent, but XML/HTML parsing libraries are often exposed to untrusted document content, which can increase risk if a vulnerable release is installed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.