Back to skill

Security audit

PPTX to Text

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its PPTX-to-text purpose, but it under-explains external document handling and uses mutable global install commands for the MinerU CLI.

Review this before installing if your presentations may contain confidential data. Prefer pinned package versions, avoid elevated privileges for installation, and only send slide decks to MinerU if its service terms and token handling are acceptable for your use case.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Global Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15-17
Vulnerability Type: Unpinned third-party dependencies installed from mutable package registries
Risk Level: Medium

bash
npm install -g mineru-open-api
# or via Go (macOS/Linux):
go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latest

Technical Analysis

The installation instructions retrieve executable third-party code without pinning it to a reviewed, immutable version. The Go command explicitly selects @latest, while the npm command implicitly resolves the registry's current release.

The npm package is installed globally and may execute package lifecycle scripts during installation. Both installation methods therefore create a supply-chain trust boundary in which the code executed by users can change after this skill has been audited. A compromised publisher account, package registry, repository, or future release could cause these commands to install attacker-controlled code.

No evidence indicates that the currently referenced package is malicious. The vulnerability is the unsafe dependency acquisition practice and the inability to reproduce the reviewed dependency state.

Attack Path

  1. An attacker compromises the dependency publisher, source repository, release process, or package-registry account.
  2. The attacker publishes a malicious version of mineru-open-api or modifies the release selected by @latest.
  3. A user follows the documented installation commands.
  4. The package manager retrieves the attacker-controlled release rather than a previously reviewed version.
  5. Malicious npm lifecycle code may execute during installation, or malicious package code executes when the installed CLI is invoked.
  6. The payload operates with the permissions and environmental access of the invoking user.

Impact Assessment

Successful exploitation could allow arbitrary code execution under the invoking us ...[truncated 453 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin both installation methods to an explicitly reviewed version rather than relying on the current registry release or @latest.
  • For npm, document an exact version, such as npm install -g mineru-open-api@X.Y.Z, after verifying that release.
  • For Go, replace @latest with a reviewed semantic version or immutable commit reference.
  • Publish expected package integrity hashes or checksums and instruct users to verify downloaded artifacts.
  • Prefer a project-local npm installation with a committed lockfile instead of a global installation where operationally feasible.
  • Review npm lifecycle scripts and consider disabling them with --ignore-scripts if the package functions correctly without installation scripts.
  • Document the verified upstream repository and release provenance so users can detect dependency confusion or publisher changes.
  • Periodically reassess pinned versions for security updates before deliberately advancing them.
  • Warn users not to perform installation with elevated privileges unless it is strictly required.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly supports URL inputs and relies on an external MinerU service/tool, but it does not clearly warn users that presentation contents may be transmitted off-host for processing. This can lead to unintentional disclosure of sensitive slide data, especially when users assume extraction is local because the skill also supports local files and frames itself as a simple conversion utility.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This line documents a default locale/language behavior of ch, while only optionally mentioning en for English. That is a natural-language locale policy concern because it imposes a specific language default without offering user choice as the primary behavior or explaining why the locale constraint is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.