Back to skill

Security audit

Python PPT Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese-oriented PowerPoint generator that runs local presentation-building code and returns the generated file to the user.

Before installing, users should expect this skill to run Python locally, create a PowerPoint file, and upload that generated file back through the platform. Install python-pptx in a virtual environment and consider pinning a reviewed version. Users who do not want Chinese-oriented styling or fonts should adjust the prompt or skill instructions before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:50
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 50-54
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

markdown
## Dependencies

```bash
pip install python-pptx
text

### Technical Analysis

The documented installation command retrieves `python-pptx` without specifying a reviewed version or verifying package integrity with cryptographic hashes. Consequently, package resolution is mutable: running the same command at different times may install different versions of the direct dependency and its transitive dependencies.

Python package installation may execute package-controlled build or installation logic. If the package distribution, publisher account, package index, or a transitive dependency is compromised, following this instruction could execute attacker-controlled code under the privileges of the user running `pip`. The absence of a lock file and integrity hashes also prevents reliable verification that installed artifacts match versions reviewed by the project maintainers.

This finding does not establish that the current `python-pptx` package is malicious. It identifies an avoidable supply-chain exposure caused by installing an unpinned package from a mutable source.

### Attack Path

1. An attacker compromises a relevant package publisher, distribution channel, or transitive dependency and publishes a malicious or backdoored release.
2. A user follows the setup instruction and runs `pip install python-pptx`.
3. Because no version or artifact hash is constrained, `pip` resolves and downloads the affected release.
4. Malicious package build or installation logic executes in the user's environment, or backdoored runtime code executes when the PowerPoint library is imported and used.
5. The payload gains the same effective permissions as the invoking process and can access resources available to that user.

### Impact Assessment

Successful exploitation could permi
...[truncated 526 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin python-pptx to an explicitly reviewed version rather than resolving the latest release:
    text
    python-pptx==<reviewed-version>
    
  2. Maintain dependencies in a lock file or requirements file that also fixes transitive versions.
  3. Require cryptographic hashes during installation, such as with a hash-locked requirements file and pip install --require-hashes -r requirements.txt.
  4. Generate hashes only after obtaining and reviewing packages through a trusted package index or controlled internal mirror.
  5. Install dependencies in an isolated virtual environment using a non-privileged account; do not run pip as root or an administrator.
  6. Add automated dependency vulnerability and provenance scanning, and update pins through a controlled review process.
  7. Document the exact supported Python and dependency versions to make installation reproducible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description is written as a prescriptive statement to generate presentations in a Chinese-oriented format and specifies Chinese font usage, which indicates a fixed language/locale expectation. The file does not offer users a language choice or explain that the skill is intentionally limited to a specific locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to generate and execute Python code and then upload the resulting file, but it provides no user-facing warning, confirmation step, or description of local file and data transfer effects. In an agent setting, silent code execution and file exfiltration increase the risk of unexpected filesystem changes, misuse of connected tools, or sending sensitive content off-box without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language documentation entirely in Chinese and presents the tool as a PPT generation library without any indication that the language choice is optional or region-specific. Under the policy, forcing a specific language without user opt-in is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.