Back to skill

Security audit

PPT制作

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local PPT generator, but it needs Review because malicious or attacker-influenced decks can inject script into previews and reference local image files outside the project.

Install only if you trust the decks and reference materials you use with it. Avoid opening generated previews from untrusted or externally influenced deck.json files until preview escaping and image path containment are fixed; update dependencies and prefer explicit invocation for sensitive documents.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_preview.js:141
Finding

Stored Cross-Site Scripting in Generated Preview HTML

Content
View full analysis
${escapeHtml(component.text)}`; } ``` The same file also inserts decoded dataset values into `innerHTML`: ```javascript function showTooltip(event, element) { const data = element.dataset; tooltip.hidden = false; tooltip.innerHTML = "" + (data.componentLabel || data.componentId) + "" + (data.componentTypeLabel || data.componentType) + (data.componentRole ? " · " + data.componentRole : "") + ""; const offset = 16; tooltip.style.left = event.clientX + offset + "px"; tooltip.style.top = event.clientY + offset + "px"; } ``` Validation does not constrain or sanitize the style object: ```javascript style: { type: "object" } ``` ### Technical Analysis Deck data is treated ...[truncated 2942 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/common.js:45
Finding

Unrestricted Local Image Path Access Through Deck Components

Content
View full analysis
`; } ``` Deck validation only requires `src` to be a string: ```javascript src: { type: "string" } ``` ### Technical Analysis `resolveAssetPath` does not enforce an asset root. It explicitly accepts absolute paths and resolves relative paths without checking whether the normalized result remains inside the project directory or another approved materials directory. Consequently, a deck can refer to locations such as: ```text /home/user/private-image.png ../../../../home/user/private-image.png ``` The generated preview converts the resolved path to a `file://` image URL. When opened locally, t ...[truncated 2146 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (78)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个面向终端用户的 PPT 制作技能,核心能力包括生成结构化演示文稿、维护 deck、预览和导出。而实际代码只是开发辅助脚本:读取命令行参数,检查目录是否存在,创建目录,并写出多个技能相关配置/模板文件。虽然其中生成了一个 starterDeck 结构,和 PPT 领域相关,但这只是为“新建子 skill/archetype”提供模板,不等于执行声明中的 PPT 生成与编辑流程。因此代码的主要目的与声明明显不一致,属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述的是一个完整的 PPT 生成与编辑工作流,而当前代码片段仅执行对 materials/ 目录的文件列表展示,属于素材盘点/辅助脚本。虽然“上传参考素材”与 PPT 生成场景可能相关,但该代码本身没有体现任何生成大纲、创建页面布局、修改组件、维护 deck.json、渲染 HTML 或导出 PPT 的行为。因此该代码片段的实际行为与声明的核心用途存在明显偏差,应判定为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
- **子技能优先(Subskill First)**:在开始创建任何 PPT 前,必须先查看 `subskills/` 目录下(或通过 `scripts/list_catalog.js`)是否已有为该场景定制的专属子技能。如果存在对应的子技能(如 `english-lesson`、`personal-intro`),

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
- **子技能优先(Subskill First)**:在开始创建任何 PPT 前,必须先查看 `subskills/` 目录下(或通过 `scripts/list_catalog.js`)是否已有为该场景定制的专属子技能。如果存在对应的子技能(如 `english-lesson`、`personal-intro`),

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
为该场景定制的专属子技能。如果存在对应的子技能(如 `english-lesson`、`personal-intro`),**必须优先阅读并严格遵循该子技能 `SKILL.md` 中的专属规范与工作流**,绝不能用当前的通用兜底流程硬做。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
为该场景定制的专属子技能。如果存在对应的子技能(如 `english-lesson`、`personal-intro`),**必须优先阅读并严格遵循该子技能 `SKILL.md` 中的专属规范与工作流**,绝不能用当前的通用兜底流程硬做。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
- `scripts/create_ppt_skill.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
- `scripts/create_ppt_skill.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 186)May include surrounding context.

md
- `scripts/create_ppt_skill.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
- `scripts/init_project.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
- `scripts/init_project.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
- `scripts/init_project.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
- `scripts/render_preview.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
- `scripts/apply_edit.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
- `scripts/apply_edit.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
- `scripts/plan_edit.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

md
- `scripts/plan_edit.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
- `scripts/edit_with_command.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
- `scripts/edit_with_command.js`

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
91% confidence
Finding

The lockfile pins fast-uri to version 3.1.0, and the supplied advisories indicate multiple URI parsing and canonicalization flaws including host confusion and SSRF-relevant edge cases. In a PPT-generation skill, dependencies may process user-supplied URLs for images or external resources, so incorrect host parsing can undermine allowlists, origin checks, or network access restrictions if this library is used in reachable code paths.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: image-size==1.2.1 — 2 advisory(ies): CVE-2025-71329 (image-size: JXL and HEIF parsers allow denial of service through infinite loops); CVE-2025-71330 (image-size: ICNS parser allows denial of service through an infinite loop)

High
Category
Supply Chain
Confidence
96% confidence
Finding

The lockfile includes image-size 1.2.1, which is reported as vulnerable to denial-of-service issues via infinite loops in multiple image parsers. This skill generates PPTs and likely handles user-provided or remotely sourced images, making malformed image files a realistic attack vector that could hang processing, consume CPU, or disrupt service availability during preview/export.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/plan_edit.js (reported line 63)May include surrounding context.

js
}

function normalizeInstruction(instruction) {
  return instruction.trim().replace(/[,。;]/g, " ").replace(/\s+/g, " ");
}

function inferSlide(deck, instruction) {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs users to place reference materials into a local materials directory and says the AI will use them to generate PPTs, but it does not prominently warn that uploaded documents may be stored locally and processed. This can create privacy and data-handling risks, especially if users place sensitive PDFs, images, or internal documents into the workspace without understanding retention and exposure boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The default prompt uses a very broad invocation phrase ('turn my topic or draft into a structured PPT deck') and the policy allows implicit invocation, which increases the chance the platform will trigger this skill for generic user requests about presentations. That can cause over-broad routing, unintended access to user content, or execution of deck-generation actions when the user did not explicitly choose this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest/template uses Chinese labels and instructional text throughout, but it does not document that the skill is Chinese-language only or offer any user language choice. That can violate language/locale policy when users are not explicitly opting into Chinese output.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/build_project.js:6

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/open_project_preview.js:6