Back to skill

Security audit

PPT Audio To Video

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently helps turn narrated slide decks into videos, but users should only run its rendering workflow on trusted local media paths.

Install only if you are comfortable with the agent running local media tools, optional dependency installation, and a model download. Use trusted slide decks and image directories, avoid attacker-controlled filenames, and treat generated CSV files from untrusted presentations as plain text unless sanitized before opening in a spreadsheet.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_from_timing_csv.py:68
Finding

FFconcat Directive Injection Through Crafted Image Filenames

Content
View full analysis

Vulnerability Details

File Location: scripts/render_from_timing_csv.py, lines 68–86
Vulnerability Type: FFconcat manifest injection
Risk Level: Medium

Vulnerable Code

python
def write_ffconcat(images, timings, output: Path):
    lines = ["ffconcat version 1.0"]
    for image, row in zip(images, timings):
        lines.append(f"file '{image.resolve()}'")
        lines.append(f"duration {row['duration_sec']:.3f}")
    lines.append(f"file '{images[-1].resolve()}'")
    output.write_text("\n".join(lines) + "\n", encoding="utf-8")


def run_ffmpeg(ffconcat_path: Path, audio_path: Path, output_path: Path, overwrite: bool):
    cmd = [
        "ffmpeg",
        "-y" if overwrite else "-n",
        "-safe",
        "0",
        "-f",
        "concat",

Technical Analysis

The script interpolates image paths directly into an FFconcat control file without escaping or rejecting FFconcat metacharacters. Unix filenames can contain single quotes, backslashes, and newline characters. A filename containing these characters can terminate the intended file directive and introduce additional directives into the generated manifest.

Image discovery only verifies that each entry is a regular file whose final suffix is .png, .jpg, or .jpeg. Therefore, an attacker can create a filename that contains injected content while still ending in an accepted extension.

The manifest is subsequently processed using ffmpeg -safe 0. This disables the concat demuxer's safe-path restrictions and may permit injected directives to reference absolute paths, paths outside the supplied image directory, or protocols supported by the installed FFmpeg build. Passing the FFmpeg command as an argument list prevents shell injection, but it does not prevent injection into the FFconcat file format.

Attack Path

  1. An attacker gains the ability to supply a slide-image directory or place files in the directory s ...[truncated 1531 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not place source filenames directly into an FFconcat control file.
  • Stage or link accepted images into a private temporary directory using generated names such as slide_0001.png, then reference only those generated names.
  • If original paths must be used, implement escaping that precisely follows FFconcat syntax and reject filenames containing carriage returns, newlines, null bytes, single quotes, or other control characters.
  • Verify after resolution that every selected image remains directly within the intended image directory.
  • Avoid -safe 0 where possible. Use safe relative paths from a controlled staging directory and retain FFmpeg's safe-path validation.
  • Create temporary manifests with restrictive permissions and unpredictable names, and remove them after rendering when persistent output is not requested.
  • Add tests using filenames containing quotes, backslashes, newlines, spaces, and directive-like text to ensure each filename remains exactly one manifest entry.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/extract_slide_outline.py:10
Finding

Spreadsheet Formula Injection in Generated Slide Outline CSV

Content
View full analysis

Vulnerability Details

File Location: scripts/extract_slide_outline.py, lines 10–32
Vulnerability Type: CSV/spreadsheet formula injection
Risk Level: Low

Vulnerable Code

python
def normalize_shape_text(text: str) -> str:
    lines = [line.strip() for line in text.splitlines()]
    lines = [line for line in lines if line]
    return " | ".join(lines)


def extract_outline(pptx_path: Path):
    prs = Presentation(str(pptx_path))
    slides = []
    for index, slide in enumerate(prs.slides, start=1):
        texts = []
        for shape in slide.shapes:
            if hasattr(shape, "text") and shape.text:
                normalized = normalize_shape_text(shape.text)
                if normalized:
                    texts.append(normalized)
        slides.append(
            {
                "slide": index,
                "text": " || ".join(texts),
            }
        )
    return slides


def write_csv(slides, output: Path):
    with output.open("w", encoding="utf-8", newline="") as fh:
        writer = csv.DictWriter(fh, fieldnames=["slide", "text"])
        writer.writeheader()
        writer.writerows(slides)

Technical Analysis

Text extracted from an untrusted PPTX presentation is written unchanged into the text field of a CSV file. Values beginning with spreadsheet formula indicators such as =, +, -, or @ may be interpreted as formulas when the resulting CSV is opened in spreadsheet software.

Python's CSV writer correctly quotes and delimits CSV records, but CSV quoting does not neutralize spreadsheet formulas. If the first extracted text on a slide begins with a dangerous character, the resulting text cell may retain that character as its first meaningful character.

Formula behavior depends on the spreadsheet application and its security configuration. Some applications restrict direct command execution, but formulas may still initiat ...[truncated 1663 chars]

Remediation
View remediation

Remediation Suggestions

  • Treat slide text as untrusted when producing files intended for spreadsheet applications.
  • Before writing a CSV cell, detect values whose first non-whitespace character is =, +, -, or @.
  • Neutralize dangerous values according to the expected consumer, such as by prefixing them with an apostrophe or another documented text marker.
  • Consider making JSON the default machine-readable output because JSON consumers do not ordinarily interpret strings as spreadsheet formulas.
  • Clearly distinguish between a raw CSV mode for trusted machine processing and a spreadsheet-safe CSV mode for interactive use.
  • Add tests covering formula prefixes, leading whitespace, tabs, carriage returns, Unicode whitespace, and quoted formula content.
  • Document that raw CSV output derived from untrusted presentations must not be opened directly in formula-evaluating spreadsheet software.
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
ripts relative to this skill directory. If the runtime has already opened this `SKILL.md`, prefer paths like `scripts/extract_slide_outline.py` and `scripts/ren

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to read and write files and execute shell commands (ffmpeg, pdftoppm, python3, curl, brew) but does not declare any tool scope or permission boundaries. In an agent environment, this increases the risk of unintended filesystem access, command execution on untrusted user-controlled paths, and dependency installation without explicit authorization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example command sets whisper-cli to -l zh, which forces Chinese transcription behavior. The document does not offer a language choice or state that the skill is limited to Chinese-language audio, creating a locale/language policy issue in the skill instructions.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render_from_timing_csv.py (reported line 110)May include surrounding context.

python
"-shortest",
        str(output_path),
    ]
    subprocess.run(cmd, check=True)


def main():

Static analysis

No suspicious patterns detected.