Back to skill

Security audit

paper-report-ppt

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated PDF-to-PPT purpose, but it needs review because it can embed arbitrary local image files from crafted slide data and its installer automatically pulls unpinned Python packages.

Review before installing. Use an isolated virtual environment, inspect the dependency list, and prefer manually installing pinned package versions. Only run the workflow on PDFs and generated slides.json files you trust, and make sure image_path values are simple filenames from the generated image manifest before creating or sharing the PPTX.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
install.py:12
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: install.py:12-18, 43-54
Vulnerability Type: Uncontrolled third-party dependency resolution
Risk Level: Medium

Complete Code Snippet

python
PACKAGES = [
    ("pptx", "python-pptx", True),
    ("fitz", "PyMuPDF", True),
    ("docx", "python-docx", True),
    ("PIL", "Pillow", True),
    ("matplotlib", "matplotlib", False),
]


def install_missing(missing):
    """pip install ONLY the missing packages.

    Only missing packages are installed to avoid uninstalling or reinstalling
    packages that are already present.
    """
    print("\nInstalling missing dependencies...")
    cmd = [
        sys.executable, "-m", "pip", "install",
        "--no-input", "--disable-pip-version-check",
    ] + [pip_name for pip_name, _ in missing]
    result = subprocess.run(cmd, capture_output=True, text=True)

Technical Analysis

The installer invokes pip using package names without exact version constraints, package hashes, a lockfile, or an explicitly trusted package index. Dependency resolution therefore selects whichever compatible releases and transitive dependencies are available from the configured index at installation time.

Python package installation can execute package build or installation logic. Consequently, the effective code installed by this project can change after the project itself has been reviewed. This is a supply-chain weakness rather than evidence that the currently named packages are malicious.

Attack Path

  1. An attacker compromises a named package, one of its transitive dependencies, or the package index used by the environment.
  2. The attacker publishes or substitutes a malicious release that remains compatible with the unpinned installation request.
  3. A user runs python install.py while the affected dependency is missing.
  4. The installer invokes pip and resolves the attacker-controlled release.
  5. Package build or installation logic executes with the privileges of the u ...[truncated 731 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed exact version.
  2. Include transitive dependencies in a generated lockfile.
  3. Require verified hashes, for example with pip install --require-hashes -r requirements.txt.
  4. Use an explicitly configured and trusted package index or an internally controlled package mirror.
  5. Perform installation in an isolated virtual environment with ordinary user privileges.
  6. Separate dependency checking from installation and require explicit user approval before downloading or installing packages.
  7. Add automated dependency vulnerability and provenance scanning to the release process.
  8. Periodically update pinned versions through a controlled review and testing workflow.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gen_pptx.py:1516
Finding

Arbitrary Local Image File Inclusion Through Crafted Slide Data

Content
View full analysis

Vulnerability Details

File Location: scripts/gen_pptx.py:1516-1546
Related Validation Limitation: scripts/validate_slides_json.py:126-133
Vulnerability Type: Path traversal and unrestricted local file read
Risk Level: Medium

Complete Code Snippet

python
def _place_image_in_area(self, slide, slide_data, images_dir,
                         area_left, area_top, area_width, area_height, t):
    """Load and center an image within the specified area."""
    image_path = slide_data.get("image_path", "")
    actual_image_file = None
    if image_path:
        if os.path.isabs(image_path):
            actual_image_file = image_path
        elif images_dir:
            actual_image_file = os.path.join(images_dir, image_path)

    if actual_image_file and os.path.isfile(actual_image_file):
        try:
            from PIL import Image as PILImage
            pil_img = PILImage.open(actual_image_file)
            img_w, img_h = pil_img.size
            aspect = img_w / img_h

            avail_w = area_width - Inches(0.4)
            avail_h = area_height - Inches(0.4)
            if avail_w / avail_h > aspect:
                final_h = avail_h
                final_w = int(final_h * aspect)
            else:
                final_w = avail_w
                final_h = int(final_w / aspect)

            img_left = area_left + (area_width - final_w) // 2
            img_top = area_top + (area_height - final_h) // 2

            slide.shapes.add_picture(
                actual_image_file,
                img_left, img_top,
                final_w, final_h,
            )

The relevant validator only checks manifest membership when a usable manifest filename list is available:

python
# C6/R3: image_path must match the manifest
if manifest_filenames and isinstance(ip, str) and ip:
    if ip not in manifest_filenames:
        errors.append(
            f"[C6/R3] Page {page_num} image_path '{ip}' "
            "is not in the manifest fil
...[truncated 2462 chars]
Remediation
View remediation

Remediation Suggestions

  1. Reject absolute image_path values unconditionally.
  2. Treat manifest filenames as simple basenames and reject directory separators, . components, and .. components.
  3. Canonically resolve both paths and enforce directory containment before opening the file:
python
base_dir = Path(images_dir).resolve(strict=True)
candidate = (base_dir / image_path).resolve(strict=True)

if not candidate.is_relative_to(base_dir):
    raise ValueError("image_path escapes images_dir")
  1. Require every image filename to appear in a successfully parsed manifest; fail closed if the manifest is missing, malformed, or empty.
  2. Move manifest and containment enforcement into gen_pptx.py so security does not depend on running a separate validator.
  3. Validate that each manifest entry is a basename and cannot itself contain an absolute or traversal path.
  4. Optionally verify the selected image's SHA-256 digest against its manifest entry before embedding it.
  5. Open untrusted images with resource limits and reject excessively large dimensions to reduce image-parser and decompression-bomb risk.
  6. Add regression tests covering absolute paths, ../ traversal, symlink escapes, malformed manifests, and valid in-directory images.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (45)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 9)May include surrounding context.

text
.pytest_cache/

# Runtime temp
.env
*.log
tmp/

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Environment and dependency inspection are materially different actions from simple content conversion because they probe the runtime and may influence subsequent command execution. When such behavior is not obvious from the declared purpose, users and automated policy systems may under-estimate the operational risk and approve the skill too broadly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Environment and dependency inspection are materially different actions from simple content conversion because they probe the runtime and may influence subsequent command execution. When such behavior is not obvious from the declared purpose, users and automated policy systems may under-estimate the operational risk and approve the skill too broadly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Environment and dependency inspection are materially different actions from simple content conversion because they probe the runtime and may influence subsequent command execution. When such behavior is not obvious from the declared purpose, users and automated policy systems may under-estimate the operational risk and approve the skill too broadly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Environment and dependency inspection are materially different actions from simple content conversion because they probe the runtime and may influence subsequent command execution. When such behavior is not obvious from the declared purpose, users and automated policy systems may under-estimate the operational risk and approve the skill too broadly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Environment and dependency inspection are materially different actions from simple content conversion because they probe the runtime and may influence subsequent command execution. When such behavior is not obvious from the declared purpose, users and automated policy systems may under-estimate the operational risk and approve the skill too broadly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Environment and dependency inspection are materially different actions from simple content conversion because they probe the runtime and may influence subsequent command execution. When such behavior is not obvious from the declared purpose, users and automated policy systems may under-estimate the operational risk and approve the skill too broadly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Environment and dependency inspection are materially different actions from simple content conversion because they probe the runtime and may influence subsequent command execution. When such behavior is not obvious from the declared purpose, users and automated policy systems may under-estimate the operational risk and approve the skill too broadly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Environment and dependency inspection are materially different actions from simple content conversion because they probe the runtime and may influence subsequent command execution. When such behavior is not obvious from the declared purpose, users and automated policy systems may under-estimate the operational risk and approve the skill too broadly.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 374)May include surrounding context.

md
| 嵌入层 | `gen_pptx.py` 用 `preserveAspectRatio` 完整显示,不裁剪 | `scripts/gen_pptx.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 379)May include surrounding context.

md
| 嵌入层 | `gen_pptx.py` 用 `preserveAspectRatio` 完整显示,不裁剪 | `scripts/gen_pptx.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 477)May include surrounding context.

md
| 嵌入层 | `gen_pptx.py` 用 `preserveAspectRatio` 完整显示,不裁剪 | `scripts/gen_pptx.py` |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially diverges from the skill manifest: it generates a DOCX speech script rather than the advertised PPTX presentation workflow. In an agent setting, this kind of capability mismatch is dangerous because orchestrators and users may grant the skill access or invoke it under false assumptions, leading to integrity issues, broken downstream automation, or misuse of outputs in a pipeline that expects editable slide decks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README encourages users to tell an AI to automatically clone and install the skill, which can cause unreviewed code retrieval and execution on the host system. In an agentic environment, this reduces user visibility into installation steps and increases the risk of executing a malicious or tampered repository, especially since installation commonly involves dependency installation and setup scripts.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes shell commands, reads and writes files, and instructs package installation, but it declares no explicit tool scope or permissions boundary. In an agent environment, this increases the chance of over-broad execution, unintended filesystem access, or silent dependency changes because the orchestrator cannot constrain the skill to its minimum required capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The DOCX formatting rules mandate Chinese-specific settings such as the CJK font 'Microsoft YaHei' and page numbering format '第 N 页'. Elsewhere the file says report language is collected from the user, but these output rules hard-code Chinese presentation conventions rather than offering a locale choice. This conflicts with the policy against forcing a specific language or locale without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states that content pages must contain sub_title and conclusion, and figure pages must contain image_caption and sub_title. However, the earlier slides.json format section and examples omit sub_title and conclusion for these page types, and the required-fields table does not list them, so the documentation actively contradicts itself about what valid input must contain.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · install.py (reported line 37)May include surrounding context.

python
missing = []
    for import_name, pip_name, required in PACKAGES:
        try:
            __import__(import_name)
        except ImportError:
            missing.append((pip_name, required))
    return missing

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installer automatically modifies the user's Python environment by installing packages without an explicit confirmation step or a clear warning. In a skill ecosystem, this increases trust and supply-chain risk because users may trigger environment changes unintentionally, and any dependency compromise would be pulled in immediately.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · install.py (reported line 54)May include surrounding context.

python
sys.executable, "-m", "pip", "install",
        "--no-input", "--disable-pip-version-check",
    ] + [pip_name for pip_name, _ in missing]
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        print("❌ 安装失败,请手动运行:")
        print(f"   pip install {' '.join(pip_name for pip_name, _ in missing)}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · install.py (reported line 67)May include surrounding context.

python
"""Run install_check.py for final verification."""
    print("\n🔍 运行环境自检...")
    try:
        result = subprocess.run(
            [sys.executable, "scripts/install_check.py"],
            capture_output=True, text=True
        )

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

文件标题与全文说明均以中文固定表述,未见提供用户语言/locale 选择,也未说明该技能仅适用于特定中文工作流或区域。根据规则,强制单一语言而无用户 opt-in 可构成自然语言政策违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire template file is written in Chinese and presents fixed Chinese headings and instructions, but it does not state that the skill is region-specific or give users an option to choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown explicitly requires the cover page to use a Chinese title plus an English title and forbids using only a single title. This is a natural-language locale policy constraint that forces a specific language format without any user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These hard rules require use of cn_title and en_title together on the cover page and present the bilingual format as mandatory. That is a language-policy violation under the audit criteria because the file does not provide a language choice or clearly justify the locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.