Back to skill

Security audit

Presentation Agent

Security checks for vulnerabilities and agentic risk

Overview

This slide-conversion skill does not show theft or persistence, but it forces owner-selected branding and theme choices into every presentation.

Install only if you are comfortable with every generated deck using the bundled Frexida visual style and attempted logo placement by default. For neutral or client-branded presentations, require an unbranded theme or remove the mandatory branding rules first. Process untrusted Markdown and Mermaid blocks in a constrained workspace, and choose output paths carefully because generated files may overwrite existing files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:60
Finding

Mandatory Owner Branding Overrides User-Neutral Presentation Generation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:60-78
Vulnerability Type: Mandatory instruction and output manipulation
Risk Level: High

The skill imposes owner-specific design and branding requirements on every generated presentation, regardless of whether the user requested or approved that branding.

Complete vulnerable code segment:

markdown
## Design Rules (Mandatory)

The following instructions originate from the owner and must be followed in every presentation.

### Fonts
- Use a Mincho-style font, such as IPAex Mincho. Do not use Gothic-style fonts by default.
- Remote fonts such as Google Fonts cannot be loaded during Marp PDF conversion. Use only locally installed fonts.
- Use sufficiently large font sizes: at least 30px for body text, 50px for h1, and 40px for h2.

### Emoji
- Do not use emoji anywhere in slides, including titles, headings, and body text.

### Logo
- Display `theme/logo.jpg` in the upper-right corner of every slide through `section::before` in `frexida.css`.
- The logo must be at least 120px so that it remains visible.
- Use an absolute path in the CSS `background-image: url()` declaration so that the logo is loaded during PDF conversion.

### Theme
- Use `theme/frexida.css`, based on navy and gold, as the default theme.

The bundled theme implements the associated automatic logo placement in theme/frexida.css:29-40:

css
/* Logo in top-right of every slide */
section::before {
  content: '';
  position: absolute;
  top: 20px;
  right: 24px;
  width: 48px;
  height: 48px;
  background-image: url('./logo.png');
  background-size: contain;
  background-repeat: no-repeat;
  z-index: 10;
}

Technical Analysis

SKILL.md is loaded as agent-level operational guidance. The directive states that owner-originated rules are mandatory for every presentation and instructs the agent to apply an owner-selected theme and logo indep ...[truncated 1813 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove language assigning mandatory priority to owner-originated branding or design instructions.
  2. Make logo insertion and custom branding explicitly opt-in through user-controlled arguments or frontmatter settings.
  3. Use an unbranded default theme when the user does not specify a theme.
  4. Ensure user instructions can disable or replace all visual defaults, including logos, fonts, colors, and layout rules.
  5. Separate conversion requirements from optional style guidance in SKILL.md.
  6. Remove automatic logo injection from the default CSS, or place it in a separately named branded theme that is selected only with explicit user approval.
  7. Add tests confirming that ordinary conversion requests do not introduce unsolicited logos, organization names, promotional material, or other attribution.
  8. Clearly disclose any selected branded theme before generating the final artifact.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code is clearly part of Tailwind CSS v3.0.16 and related PostCSS tooling. It defines selector parsers, AST node helpers, nested CSS expansion, utility and variant generation, color parsing, and stylesheet processing. There is no evidence of Markdown parsing, Marp integration, slide deck generation, PDF/PPTX/HTML export, Mermaid rendering, or presentation creation workflows. This is not a minor implementation detail of a Markdown-to-slides skill; it is a materially different primary function centered on CSS processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared skill is about turning Markdown into presentation slides via Marp. The supplied code does not parse Markdown, generate slides, invoke Marp, render PDF/PPTX/HTML presentations, or handle Mermaid/data graph presentation generation. Instead, it contains minified/bundled JavaScript for Tailwind CSS and Autoprefixer/PostCSS processing: scanning class content, generating stylesheet rules, handling @apply/@screen, parsing CSS values/selectors, and applying vendor prefixes. That is a materially different primary purpose, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code is not related to Markdown-to-slide conversion, Marp, PDF/PPTX/HTML slide export, Mermaid rendering, or presentation generation. Instead, it is a bundled Tailwind CSS runtime for the browser/CDN that monitors the document, collects class names, processes Tailwind directives with PostCSS and Autoprefixer, and injects generated CSS into the page. This is a materially different primary purpose and introduces undeclared capabilities involving DOM observation and dynamic style generation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to invoke shell commands and write files, but it does not declare any explicit tool scope such as allowed-tools or permissions. That creates an authorization gap where a host may expose broader shell or filesystem capabilities than the skill actually needs, increasing the blast radius if the skill is misused or if untrusted Markdown content influences downstream commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file switches into mandatory Japanese-language instructions and states they must always be followed for all presentations. This imposes a specific language/locale expectation without documenting user opt-in or presenting an alternative, which is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-of-file description is written in Japanese and does not offer any language choice or indicate that the skill is intentionally limited to a Japanese-speaking context. Under the policy, forcing a specific language without user opt-in or clear justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code writes extracted Mermaid content to disk and invokes the external mmdc renderer, but there is no confirmation prompt, print/log message, or explanatory comment warning the user that temporary files are created and an external command is executed. Under the code-file criteria, these safety-relevant operations lack visible disclosure in the file itself.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
88% confidence
Finding

The script writes untrusted Mermaid content to a temporary .mmd file and invokes the external Mermaid CLI (mmdc) on it without validation or sandboxing. While shell injection is avoided by using an argument list, this still exposes the system to parser/renderer attacks, resource exhaustion, or unsafe behavior in downstream tooling when processing attacker-controlled diagram content.

Content

Scanner excerpt · scripts/mermaid_preprocess.py (reported line 15)May include surrounding context.

python
png = os.path.join(imgdir, f"mermaid_{idx}.png")
    with open(mmd, 'w') as f:
        f.write(m.group(1))
    subprocess.run(
        ["mmdc", "-i", mmd, "-o", png, "-b", "transparent", "--width", "1200"],
        stdin=subprocess.DEVNULL, capture_output=True, timeout=30
    )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script writes the processed content directly to outfile, which can overwrite an existing file, but the code provides no user-facing disclosure, confirmation, or warning about this destructive file-write behavior. For code files, overwriting user files without any visible notice matches the missing-warning criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script creates an output directory and temporary files/directories, then later deletes the temporary artifacts, but it provides no confirmation prompt, warning message, or descriptive comment aimed at the user about these filesystem changes. For a code file, these are safety-relevant file operations and the only user-facing output is the final success message after completion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The stylesheet explicitly prioritizes 'Noto Sans JP' for all section content, which can be interpreted as enforcing a specific language/locale preference across the skill output. The file provides no user opt-in or documented region-specific justification for this locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

At L24-L25, the code checks d.env.LANG for a cn prefix and then prints a warning message in Chinese. This creates locale-specific behavior based on environment settings rather than an explicit user choice, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.