Back to skill

Security audit

Pptx Extract

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently helps extract PowerPoint content with MinerU, but users should be aware it depends on an external CLI/API and may process presentation data outside the local environment.

Install only from the expected MinerU/OpenDataLab package source, prefer pinning a reviewed version when possible, and avoid using this with confidential or regulated presentations unless third-party MinerU processing is approved for your environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party CLI Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–17
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
npm install -g mineru-open-api
# or via Go (macOS/Linux):
go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latest

Technical Analysis

The documented installation commands retrieve and install third-party software without selecting a reviewed, immutable version. The Go command explicitly uses the mutable @latest version, while the npm command omits a version entirely and therefore resolves the package registry's current default release.

The npm installation is global and may execute package lifecycle scripts during installation. The project provides no lockfile, checksum, signature verification, vendored implementation, or other mechanism that binds installation to the code reviewed during this audit. Consequently, the effective code installed by these commands can change after the Skill has been reviewed.

This creates a supply-chain risk if the upstream package, publisher account, package registry, release process, or referenced repository is compromised. There is no evidence in the audited file that the named package is currently malicious; the finding concerns the unsafe mutable dependency installation practice.

Attack Path

  1. An attacker compromises the upstream package publisher, repository, release pipeline, or registry account.
  2. The attacker publishes a malicious release under the expected package name or replaces the release resolved by latest.
  3. A user or agent follows the installation instructions in SKILL.md.
  4. The package manager retrieves the attacker-controlled mutable release.
  5. For npm, malicious lifecycle scripts may execute during installation; otherwise, the malicious code executes when mineru-open-api is invoked.
  6. The payload operates with the privileges of the in ...[truncated 699 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin both installation methods to a specific, reviewed release rather than relying on an omitted version or @latest.
  2. For npm, document an exact version and, where feasible, use a lockfile and integrity metadata.
  3. For Go, replace @latest with a specific semantic version or reviewed immutable commit.
  4. Publish expected checksums or signature-verification instructions for release artifacts.
  5. Avoid global installation where possible. Prefer a project-local dependency, isolated environment, or container running without elevated privileges.
  6. Disable npm lifecycle scripts during installation when the package does not require them, and verify functionality before recommending that configuration.
  7. Document the expected publisher, canonical source repository, audited version, and package provenance so users can detect typosquatting or publisher changes.
  8. Establish a controlled dependency-update process in which new releases are reviewed and their pinned versions and integrity values are updated explicitly.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly supports extracting from a URL and uses the MinerU Open API, but it does not clearly disclose that document contents and referenced remote files may be transmitted to an external third-party service for processing. This can lead users to send sensitive presentation data off-platform without informed consent, creating confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.