Back to skill

Security audit

jackyshen-gen-pptx

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a PPTX creation/editing helper, but it needs Review because some instructions broaden into external image-generation/subagent workflows and its LibreOffice helper can unsafely load native code from a shared temporary path.

Review before installing. Use it in an isolated workspace, avoid shared multi-user hosts, be cautious with sensitive decks when -IMG or QA could send content to other skills/services, and pin or review install dependencies. The PPTX functionality is coherent, but the image-generation workflow and LibreOffice shim should be fixed or explicitly controlled before routine use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/office/soffice.py:28
Finding

Predictable Shared Temporary Library Enables LD_PRELOAD Code Execution

Content
View full analysis

Vulnerability Details

File Location: scripts/office/soffice.py:28-30, 41, 49-64
Vulnerability Type: Unsafe temporary file handling leading to local code execution
Risk Level: High

Vulnerable Code

python
def get_soffice_env() -> dict:
    env = os.environ.copy()
    env["SAL_USE_VCLPLUGIN"] = "svp"

    if _needs_shim():
        shim = _ensure_shim()
        env["LD_PRELOAD"] = str(shim)

    return env
python
_SHIM_SO = Path(tempfile.gettempdir()) / "lo_socket_shim.so"
python
def _ensure_shim() -> Path:
    if _SHIM_SO.exists():
        return _SHIM_SO

    src = Path(tempfile.gettempdir()) / "lo_socket_shim.c"
    src.write_text(_SHIM_SOURCE)
    subprocess.run(
        ["gcc", "-shared", "-fPIC", "-o", str(_SHIM_SO), str(src), "-ldl"],
        check=True,
        capture_output=True,
    )
    src.unlink()
    return _SHIM_SO

The resulting environment is used at scripts/thumbnail.py:161-174 when launching LibreOffice:

python
result = subprocess.run(
    [
        "soffice",
        "--headless",
        "--convert-to",
        "pdf",
        "--outdir",
        str(temp_dir),
        str(pptx_path),
    ],
    capture_output=True,
    text=True,
    env=get_soffice_env(),
)

Technical Analysis

When the host blocks creation of AF_UNIX sockets, _needs_shim() returns True and _ensure_shim() supplies a native library through LD_PRELOAD.

The library path is the fixed, predictable name /tmp/lo_socket_shim.so. If that path already exists, the code trusts it solely based on Path.exists(). It does not verify that the object:

  • Is a regular file rather than a symlink or another special object.
  • Is owned by the current user.
  • Has safe permissions.
  • Was generated from the embedded source.
  • Has an expected digest or other integrity property.

The source path /tmp/lo_socket_shim.c is likewise predictable and created without a private temporary directory or exclusive file creation. These pro ...[truncated 2006 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a unique private temporary directory with permissions set to 0700, such as through tempfile.TemporaryDirectory().
  2. Place both the C source and compiled library inside that private directory rather than directly under the shared system temporary directory.
  3. Use exclusive creation semantics and reject symlinks when creating files.
  4. Do not reuse a library merely because a fixed path exists. Generate it for each trusted execution or maintain it in an application-owned directory unavailable to other users.
  5. Before assigning the library to LD_PRELOAD, verify with lstat() that it is a regular file, is owned by the current effective user, and is not writable by group or other users.
  6. Where reuse is necessary, verify the library against a trusted digest and protect both the directory and file from modification.
  7. Compile to a unique temporary output and atomically rename it only within the same private directory.
  8. Remove the source, library, and private directory after LibreOffice exits.
  9. Consider avoiding LD_PRELOAD entirely by configuring LibreOffice through a supported sandbox-compatible mechanism.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (65)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description promises broad PPTX manipulation, but the visible instructions prominently include conversion of decks to PDF/JPEG and thumbnail generation through external tools. Undeclared rendering/output behaviors matter because they introduce additional file creation, subprocess execution, and potential data exposure beyond what a user may expect from simple deck editing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest scopes the skill to creating, editing, reading, and extracting from .pptx presentation files, but this module operates on WordprocessingML content such as word/document.xml, w:ins, and w:del, and even opens .docx zip archives. That is a substantive behavior mismatch because the code targets Word document redlines instead of slide decks or presentation structures.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/office/schemas/ecma/fouth-edition/opc-contentTypes.xsd (reported line 1)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<xsd:schema xmlns="http://schemas.openxmlformats.org/package/2006/relationships"
  xmlns:xsd="http://www.w3.org/2001/XMLSchema"
  targetNamespace="http://schemas.openxmlformats.org/package/2006/relationships"

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/office/schemas/ecma/fouth-edition/opc-coreProperties.xsd (reported line 1)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<xsd:schema xmlns="http://schemas.openxmlformats.org/package/2006/relationships"
  xmlns:xsd="http://www.w3.org/2001/XMLSchema"
  targetNamespace="http://schemas.openxmlformats.org/package/2006/relationships"

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/office/schemas/ecma/fouth-edition/opc-relationships.xsd (reported line 1)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<xsd:schema xmlns="http://schemas.openxmlformats.org/package/2006/relationships"
  xmlns:xsd="http://www.w3.org/2001/XMLSchema"
  targetNamespace="http://schemas.openxmlformats.org/package/2006/relationships"

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/office/soffice.py (reported line 25)May include surrounding context.

python
def get_soffice_env() -> dict:
    env = os.environ.copy()
    env["SAL_USE_VCLPLUGIN"] = "svp"

    if _needs_shim():

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements validation logic for Word .docx tracked changes even though the declared skill scope is PowerPoint .pptx. This scope mismatch expands the skill's effective capabilities beyond what users and reviewers would expect, undermining trust boundaries and increasing the chance that unsupported document types or hidden functionality are exposed without appropriate review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill invokes shell commands and performs file read/write operations, but it declares no explicit tool scope such as allowed-tools or permissions. That creates an overbroad execution surface where an agent may run filesystem and subprocess actions without a transparent contract, increasing the risk of unintended command execution or document processing on untrusted files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This skill file presents its operational instructions in Chinese, which effectively forces a specific language for users without any opt-in or alternative. The stated policy requires flagging language or locale constraints unless the skill offers a choice or clearly documents a justified regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 markdown 文件包含自然语言指令“幻灯片的具体内容应使用{Chinese}。占位符内容应保留为{Chinese}。”,这会将技能输出限定为特定语言。根据规则,若未提供用户选择或未说明这是特定区域/合规场景所必需,则属于语言/locale policy violation。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to invoke external image-generation capabilities and download generated files into the working directory, expanding behavior from local PPTX manipulation into networked content generation and file ingestion. This increases attack surface by enabling unbounded external interactions, unexpected data egress to third-party services, and introduction of untrusted remote content into outputs without being clearly declared in the skill scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Requiring the launch of subagents to call other skills gives this skill orchestration behavior beyond its declared purpose of PPTX creation and editing. That delegation can bypass user expectations and policy boundaries, causing uncontrolled tool chaining, hidden external actions, and broader propagation of sensitive prompt or document content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.