Back to skill

Security audit

PPTX Parse

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PowerPoint-to-Markdown wrapper around MinerU, with normal but important privacy and supply-chain cautions.

Before installing, confirm that MinerU's data handling is acceptable for your presentations, especially confidential or regulated decks. Prefer a pinned or reviewed mineru-open-api version and run parsing with only the files and token needed for the task.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party CLI Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15 and 17
Vulnerability Type: Unpinned third-party dependencies from mutable external sources
Risk Level: Medium

Vulnerable Code

bash
npm install -g mineru-open-api
# or via Go (macOS/Linux):
go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latest

Technical Analysis

The documented installation commands retrieve and install third-party code without pinning an audited version or verifying an integrity hash. The Go command explicitly selects @latest, while the npm command implicitly resolves the latest package version available from the configured registry.

The npm command also performs a global installation. Depending on the local npm configuration and user privileges, package lifecycle scripts or a malicious executable supplied by a compromised release could run with broad access to the user's files, environment variables, and development credentials.

This creates a supply-chain risk: the effective code installed when users follow the instructions can change after the skill has been reviewed. Exploitation would require compromise or malicious control of the package, repository, maintainer account, registry resolution, or release process. The audited file does not establish that the current upstream package is malicious.

Attack Path

  1. An attacker compromises the npm package, upstream repository, maintainer credentials, release pipeline, or another relevant distribution channel.
  2. The attacker publishes a malicious version as the latest release.
  3. A user or agent follows the installation instructions in SKILL.md.
  4. The unpinned command downloads the attacker-controlled release.
  5. Malicious installation logic, lifecycle scripts, build logic, or the installed CLI executes with the invoking user's privileges.
  6. The payload may access files and credentials available to that user or alter tools and project data within that user's permission b ...[truncated 504 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin both installation methods to a specific, reviewed release rather than resolving the latest version.
  • Replace @latest with an immutable Go module version, preferably a reviewed release tag or commit.
  • Specify an exact npm package version and use a lockfile where installation occurs within a managed project.
  • Avoid global npm installation where possible; use a project-local dependency or an isolated execution environment.
  • Verify downloaded artifacts using trusted checksums, signatures, or package provenance attestations.
  • Document the expected publisher, repository, version, and integrity value so users can validate package provenance.
  • Review dependency updates before changing the pinned version and use automated supply-chain scanning.
  • Perform document parsing in a sandbox with minimal filesystem access and without unrelated secrets in the environment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises parsing local files and URLs via MinerU but does not clearly warn that presentation contents may be transmitted to an external third-party service. Users may unknowingly send sensitive slide content, embedded notes, or confidential URLs off-host, creating a real privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The authentication section explains how to configure a MinerU API token for full parsing but omits any warning that token-authenticated use likely sends presentation data to a third-party service. This can mislead users into treating the skill as a local parser when it may process proprietary decks externally, increasing the chance of accidental disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.