Back to skill

Security audit

PPT压缩

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward PPTX compression skill with normal lossy-compression and resource-use cautions, and no evidence of hidden data access, persistence, or exfiltration.

Install only if you are comfortable running a local PPTX media compressor. Use it on trusted presentations where possible, keep the original file, review the compressed output for quality loss or removed thumbnails/comments, and be cautious with very large or untrusted PPTX files because archive processing is not size-limited.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/compress.py:329
Finding

Unbounded PPTX Decompression and In-Memory Archive Retention

Content
View full analysis

Vulnerability Details

File Location: scripts/compress.py, lines 329-344
Vulnerability Type: Uncontrolled resource consumption through malicious ZIP/PPTX input
Risk Level: Medium

Vulnerable Code:

python
entries = {}
images_processed = 0
images_saved = 0
videos_processed = 0
videos_saved = 0

tmp_dir = tempfile.mkdtemp(prefix="pptc_")

try:
    with zipfile.ZipFile(input_path, "r") as zin:
        for info in zin.infolist():
            name = info.filename
            if name.endswith("/"):
                continue

            data = zin.read(name)

Technical Analysis

The application treats the supplied PPTX as a ZIP archive and calls zin.read(name) for every non-directory member. Each member is fully decompressed into memory. The resulting content is subsequently retained in the entries dictionary until the entire output archive is written.

The implementation does not enforce limits on:

  • The number of archive members
  • The uncompressed size of an individual member
  • The cumulative uncompressed size
  • The ratio between compressed and uncompressed sizes
  • The amount of memory available for retained archive data

Consequently, a small malicious PPTX containing highly compressible data can expand to a very large size. An archive with many moderately large entries can produce the same outcome. Media files may also be copied to temporary storage for processing, potentially causing disk exhaustion in addition to memory exhaustion.

The archive is not extracted using member-controlled filesystem paths, so this finding is not a ZIP path traversal vulnerability.

Attack Path

  1. An attacker creates a valid ZIP-based PPTX containing one or more entries with extremely large declared or actual uncompressed sizes.
  2. The attacker provides the presentation to a user or service that invokes this Skill.
  3. The compressor enumerates the entries with zin.infolist().

...[truncated 743 chars]

Remediation
View remediation

Remediation Suggestions

  • Check ZipInfo.file_size before reading each member and reject entries above a documented per-entry limit.
  • Track cumulative uncompressed size and stop processing when a global limit is exceeded.
  • Reject archives containing an excessive number of members.
  • Calculate and constrain the compression ratio using file_size and compress_size, taking care to handle zero-size values.
  • Process and write entries incrementally rather than retaining the entire archive in entries.
  • Apply operating-system resource controls, including memory, CPU, execution-time, and temporary-disk quotas, when handling untrusted files.
  • Preserve Pillow's decompression-bomb protections and consider treating PIL.Image.DecompressionBombWarning as an error.
  • Validate limits before invoking ffmpeg and constrain the size of temporary video files.
  • Return a clear validation error when an archive exceeds any configured limit.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned Pillow Dependency Produces Non-Reproducible Installations

Content
View full analysis

Vulnerability Details

File Location: requirements.txt, line 1
Vulnerability Type: Unpinned third-party dependency without integrity verification
Risk Level: Low

Vulnerable Code:

text
Pillow>=10.0.0

Related installation guidance in SKILL.md:16 also instructs users to run:

bash
pip install Pillow

Technical Analysis

Pillow is the legitimate package name, and the reviewed project contains no evidence of dependency confusion or typosquatting. However, the lower-bound-only constraint permits pip to install any future version satisfying >=10.0.0. The documentation is even less restrictive because it installs the latest version available from the user's configured package index.

This prevents reproducible dependency resolution and means installations can receive code that was not available for review when this Skill was audited. No hashes or lock file are provided to verify the integrity of the resolved distribution.

This is a supply-chain hardening weakness rather than evidence that the current Pillow package is malicious.

Attack Path

  1. A user installs the Skill's dependencies using pip install -r requirements.txt or follows the documented pip install Pillow command.
  2. pip queries the configured package index and resolves any available Pillow version satisfying the unconstrained requirement.
  3. A future compromised release, compromised package index, or maliciously substituted distribution is downloaded without hash verification.
  4. Package installation or subsequent import executes the substituted dependency with the privileges of the user running pip or the compressor.

Impact Assessment

If the dependency source or a future accepted release is compromised, malicious dependency code could execute with the same privileges as the installing or running user. That could expose files and environment variables available to that account or modify user-accessib ...[truncated 179 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin Pillow to a specifically reviewed version, for example Pillow==<reviewed-version>.
  • Generate a lock file containing hashes for all platform-specific distributions that the project supports.
  • Install with hash enforcement, such as pip install --require-hashes -r requirements.txt.
  • Update SKILL.md and the import error message to direct users to the pinned requirements file rather than an unrestricted pip install Pillow command.
  • Document the trusted package index and disable unintended supplemental indexes where practical.
  • Use automated dependency scanning and a controlled update process to keep the pinned version current with security fixes.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
python scripts/compress.py <input.pptx> [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
python scripts/compress.py <input.pptx> [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
python scripts/compress.py <input.pptx> [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
python scripts/compress.py <input.pptx> [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
python scripts/compress.py <input.pptx> [options]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises shell-based usage (python scripts/compress.py, optional ffmpeg) but does not declare any explicit tool scope or allowed tools. In an agent environment, this can cause the runtime to invoke shell capabilities without least-privilege constraints, increasing the chance of unintended command execution or unsafe tool use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill performs destructive transformations: lossy image recompression, PNG-to-JPEG conversion, metadata/comment stripping, and possible video transcoding. Without a clear warning that content fidelity, transparency, thumbnails, comments, and embedded media quality may be permanently altered, users or agents may overwrite important files or unintentionally destroy business-relevant information.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
elif sys.platform == "darwin":
        print("  brew install ffmpeg", file=sys.stderr)
    else:
        print("  sudo apt install ffmpeg   # Debian/Ubuntu", file=sys.stderr)
        print("  sudo dnf install ffmpeg   # Fedora", file=sys.stderr)
        print("  sudo pacman -S ffmpeg     # Arch", file=sys.stderr)
    print(file=sys.stderr)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/compress.py (reported line 75)May include surrounding context.

python
elif sys.platform == "darwin":
        print("  brew install ffmpeg", file=sys.stderr)
    else:
        print("  sudo apt install ffmpeg   # Debian/Ubuntu", file=sys.stderr)
        print("  sudo dnf install ffmpeg   # Fedora", file=sys.stderr)
        print("  sudo pacman -S ffmpeg     # Arch", file=sys.stderr)
    print(file=sys.stderr)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/compress.py (reported line 76)May include surrounding context.

python
elif sys.platform == "darwin":
        print("  brew install ffmpeg", file=sys.stderr)
    else:
        print("  sudo apt install ffmpeg   # Debian/Ubuntu", file=sys.stderr)
        print("  sudo dnf install ffmpeg   # Fedora", file=sys.stderr)
        print("  sudo pacman -S ffmpeg     # Arch", file=sys.stderr)
    print(file=sys.stderr)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/compress.py (reported line 77)May include surrounding context.

python
elif sys.platform == "darwin":
        print("  brew install ffmpeg", file=sys.stderr)
    else:
        print("  sudo apt install ffmpeg   # Debian/Ubuntu", file=sys.stderr)
        print("  sudo dnf install ffmpeg   # Fedora", file=sys.stderr)
        print("  sudo pacman -S ffmpeg     # Arch", file=sys.stderr)
    print(file=sys.stderr)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/compress.py (reported line 241)May include surrounding context.

python
cmd.append(out_file)

    try:
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=300)
        if result.returncode != 0:
            print(f"  [视频压缩失败] {Path(name).name}: ffmpeg 返回 {result.returncode}", file=sys.stderr)
            if result.stderr:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

文件中的技能描述完全以中文呈现,未提供语言选择或说明该技能仅面向中文用户的明确理由。按照规则,若技能强制特定语言且没有用户选择或正当限定,可能构成自然语言层面的语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified as Pillow>=10.0.0, which allows any newer version to be installed at build time. This makes builds non-reproducible and can unexpectedly pull in a vulnerable or breaking release, especially for an image-processing skill that handles potentially untrusted PPTX-embedded media.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
Pillow>=10.0.0

Unverifiable Dependency: Pillow has 16 known advisory(ies) (CVE-2016-2533 (Pillow buffer overflow in ImagingPcdDecode); CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2021-27922 (Pillow Uncontrolled Resource Consumption) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
85% confidence
Finding

Pillow has a history of security advisories, including memory safety and resource-consumption issues, and the manifest does not pin a reviewed version. In this skill, Pillow is used for PPTX compression, meaning it may process attacker-controlled embedded images from uploaded presentations; that context increases risk because malformed files could trigger known or newly introduced vulnerable code paths.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.