Back to skill

Security audit

Marp Slide Expert

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Marp slide-making helper with disclosed local rendering, linting, and asset-prep workflows; the main risks are normal install and command-execution precautions.

Before installing, prefer pinned package versions or a reviewed Git commit, be cautious with global installation, and remember that speaker notes placed in HTML comments are hidden from rendered slides but remain in the source markdown. Only run the optional Obsidian plugin patch if you understand it modifies that local plugin file.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (72)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
| Scenario | Pattern |
|---|---|
| Cover | `<!-- _class: cover -->` + `# Title` + `## Subtitle` |
| Major section break | `<!-- _class: divider -->` + `# Section Name` |
| Text only / text + table | Plain markdown, default content slide |
| **Two columns** | `<div class="cols cols-2">` — 并列论点、两套方案 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
node scripts/svg-lint.mjs deck.marp.md # 6 deterministic checks

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

md
node scripts/svg-lint.mjs deck.marp.md # 6 deterministic checks

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
| Code block | 1 line per code line — no exceptions, no partial credit |
| Quote / tip / warn box (`>`) | Every wrapped line inside the box |
| Heading | Count it — `##` costs 1 line before the body starts |
| Speaker note / any HTML comment `<!-- -->` | **0 lines** — comments never render, so they never count |

A slide is a **budget of 15 total**, not 15 per element. `##` title (1) + table 6 rows (6) + 2 bullets (2) + closing paragraph (2 lines) = 11 → fine. Add a 5-line code block and you're at 16 → split.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

md
- On-premise: compliance first
- Hybrid: best cost

<!--
Speaker notes:
- "Hybrid" is the newest option; long-time customers ask about it most.
- Case: a bank went on-premise, 8M contract.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
|---|---|
| Image shows as markdown text instead of background | Path has unescaped spaces — wrap in `<...>` |
| Two images stack weirdly | Missing `vertical` keyword for portrait images |
| Content cut off at bottom | Slide has > 15 rendered lines — split, or move speaker-only detail into a `<!-- -->` note |
| Table rows truncated horizontally | Table too wide — keep ≤ 4 columns or shrink font in CSS |
| Table renders at half width | marp's default theme sets `table { display: block }` — the block box stretches but the inner anonymous table shrink-wraps. Fix with `display: table !important` (already in style-bootstrap) |
| Whole slide shows SVG source code | Missing `--html` at render time (columns do **not** need it — only inline SVG) |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/infographic-gallery.marp.md (reported line 48)May include surrounding context.

md
_paginate: skip
---

<!--
  渲染命令(含内联 SVG,必须带 --html):
  marp examples/infographic-gallery.marp.md --html --pdf --allow-local-files

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/infographic-gallery.marp.md (reported line 48)May include surrounding context.

md
_paginate: skip
---

<!--
  渲染命令(含内联 SVG,必须带 --html):
  marp examples/infographic-gallery.marp.md --html --pdf --allow-local-files

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/infographics-svg/craft/qa.md (reported line 50)May include surrounding context.

md
| **语义** | 有没有孤立的节点(声明了关系却没画线)?不查图例能读懂线的关系吗? |
| **层级** | 是不是所有节点一样大(= 没有重点)?色相是否超过 3 个? |
| **对比** | 深底上的文字够亮吗?浅底上的文字够深吗?灰度打印还读得出吗? |
| **贴底** | 底部元素压到 footer 了吗?(→ 加 `<!-- _class: diagram -->`) |

### 修完要重渲

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/infographics-svg/craft/qa.md (reported line 50)May include surrounding context.

md
| **语义** | 有没有孤立的节点(声明了关系却没画线)?不查图例能读懂线的关系吗? |
| **层级** | 是不是所有节点一样大(= 没有重点)?色相是否超过 3 个? |
| **对比** | 深底上的文字够亮吗?浅底上的文字够深吗?灰度打印还读得出吗? |
| **贴底** | 底部元素压到 footer 了吗?(→ 加 `<!-- _class: diagram -->`) |

### 修完要重渲

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/infographics-svg/craft/qa.md (reported line 150)May include surrounding context.

md
- 表格里用文字描述代替尖括号:"CSS grid + 分栏 div"、"内联 SVG"
- 或者给 lint 加豁免指令 `<!-- svg-lint-ignore: blank-line, page-break -->` 局部禁用某些检查

## 4. 模板里的 `<!-- N=5 时 -->` 注释会引入空行

写示例 SVG 时常会写 `<!-- 这是 N=5 的情况 -->` 加注释。但 SVG 块内**禁止空行**,注释本身或前后空行都会触发 lint。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/infographics-svg/craft/qa.md (reported line 150)May include surrounding context.

md
- 表格里用文字描述代替尖括号:"CSS grid + 分栏 div"、"内联 SVG"
- 或者给 lint 加豁免指令 `<!-- svg-lint-ignore: blank-line, page-break -->` 局部禁用某些检查

## 4. 模板里的 `<!-- N=5 时 -->` 注释会引入空行

写示例 SVG 时常会写 `<!-- 这是 N=5 的情况 -->` 加注释。但 SVG 块内**禁止空行**,注释本身或前后空行都会触发 lint。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/infographics-svg/metaphors.md (reported line 177)May include surrounding context.

需要"线宽递增 = 势能积累"语义时用。要点是线粗细的渐变要足够明显,否则肉眼分不出来——建议梯度(2.5 / 4 / 6 / 8),比(2.5 / 4 / 5.5 / 7)更容易看出。

html
<svg viewBox="0 0 1020 460" width="100%">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/infographics-svg/metaphors.md (reported line 177)May include surrounding context.

需要"线宽递增 = 势能积累"语义时用。要点是线粗细的渐变要足够明显,否则肉眼分不出来——建议梯度(2.5 / 4 / 6 / 8),比(2.5 / 4 / 5.5 / 7)更容易看出。

html
<svg viewBox="0 0 1020 460" width="100%">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/slide-density.md (reported line 62)May include surrounding context.

md
- On-premise: compliance first
- Hybrid: best cost

<!--
Speaker notes: Hybrid is the newest option; long-time customers ask about it most.
Case: a bank went on-premise, 8M contract.
If asked about pricing, jump to the table on the next slide.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/slide-density.md (reported line 74)May include surrounding context.

md
Two traps:

- A `---` inside a comment is **still** a page break. Never write one inside a note.
- Marpit directives also use `<!-- -->`; those must start with `_` (`<!-- _class: cover -->`) to stay active. Speaker notes must not start with `_`.

**Rule of thumb: adding a second slide is a cost to the audience. Adding a speaker note is free. Reach for the note first.**

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/style-bootstrap.md (reported line 212)May include surrounding context.

md
The frontmatter is **YAML**. An HTML comment inside it breaks the parse, and the failure is silent and total — the whole `style:` block is discarded, so the deck renders in marp's default theme with no colours, no column grids, and no table fix. No warning is printed.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/build-gallery.mjs (reported line 108)May include surrounding context.

js
const esc = (s) => s.replace(/&/g, '&').replace(/</g, '<').replace(/>/g, '>');

const diagramSlide = (title, svg, note) => `<!-- _class: diagram -->

## ${title}

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/svg-lint.mjs (reported line 187)May include surrounding context.

js
}

// 豁免写法(代码写在指令行的逗号列表里,其余行写理由):
//   <!-- svg-lint-ignore: duplicate-id
//        理由写在这里 -->
// 显式豁免某些检查。
// 用途:references/ 里的模板故意复用 a1 这类占位 id(实际使用时按图序重编号),

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/svg-lint.mjs (reported line 216)May include surrounding context.

js
}

// 豁免写法(代码写在指令行的逗号列表里,其余行写理由):
//   <!-- svg-lint-ignore: duplicate-id
//        理由写在这里 -->
// 显式豁免某些检查。
// 用途:references/ 里的模板故意复用 a1 这类占位 id(实际使用时按图序重编号),

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/svg-lint.mjs (reported line 194)May include surrounding context.

js
// 紧凑预览图故意用非 1020 宽度。豁免必须写在文件里,不做静默跳过。
function parseIgnores(text) {
  const out = new Set();
  // 指令可以出现在注释的任何位置,不要求紧跟 <!--
  for (const d of text.match(/<!--[\s\S]*?svg-lint-ignore:[\s\S]*?-->/g) || []) {
    // 只取指令行的逗号列表;其余行是给人看的理由
    const body = d.replace(/<!--[\s\S]*?svg-lint-ignore:/, '').trim().split('\n')[0];

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/svg-lint.mjs (reported line 197)May include surrounding context.

js
// 指令可以出现在注释的任何位置,不要求紧跟 <!--
  for (const d of text.match(/<!--[\s\S]*?svg-lint-ignore:[\s\S]*?-->/g) || []) {
    // 只取指令行的逗号列表;其余行是给人看的理由
    const body = d.replace(/<!--[\s\S]*?svg-lint-ignore:/, '').trim().split('\n')[0];
    for (const code of body.split(',')) {
      const t = code.replace(/[*_`]/g, '').trim();
      if (t) out.add(t);

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to execute npx skills add mebusw/marp-slide-expert without pinning a specific version. npx resolves and executes the latest package version at install time, so a compromised upstream package, account takeover, or malicious new release could cause arbitrary code execution on the user's machine during installation. In a skill-installation context this is more dangerous because the command is presented as the primary onboarding path and is likely to be copied verbatim.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The global install variant npx skills add -g mebusw/marp-slide-expert has the same supply-chain risk as the local install command, but with potentially broader system impact because it affects all projects. If the transient skills package fetched by npx is malicious or tampered with, it may execute arbitrary code with the user's privileges while setting up a globally available skill. The skill context increases exposure because users are explicitly told this is the normal installation route.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The fallback command npx -y @marp-team/marp-cli --version fetches and executes the latest published package without version pinning. Even though it only asks for --version, arbitrary package install scripts or binary execution can still run, so a malicious or compromised release could execute code on the host. In this documentation context the risk is real but appears negligent rather than malicious, since it is standard convenience guidance for bootstrapping a dependency.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.