T09 · Insecure Skill Coding Practices
- Location
scripts/merge_slides.py:56- Finding
Unhardened XML Parsing of User-Controlled PPTX Content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed local HTML-to-PowerPoint workflow with helper scripts, but users should be aware it writes files, runs local Python/Node code, and has some dependency and parser hardening gaps.
Install and run this only in a project or virtual environment, avoid global npm installs when possible, do not process PPTX files from untrusted sources with the merge helper, and review output paths because the workflow creates local tmp files and PPTX outputs.
scripts/merge_slides.py:56Unhardened XML Parsing of User-Controlled PPTX Content
pptxgenjs.md:238Unpinned and Global Third-Party Dependency Installation Instructions
The declared description promises an end-to-end, pixel-faithful HTML/design to PowerPoint conversion workflow. The supplied code chunk is only a chart-detection helper script. Its scope is limited to extracting chart-related information from one HTML file and optional intermediate files (layout_map.json, svg_inventory.json, design_spec.json), then generating pptxgenjs snippets and charts.json. This is a materially narrower and different purpose than full PPT conversion. While chart extraction could be a supporting component within such a pipeline, the code itself does not implement the declared primary capability of producing PPT slides, handling arbitrary page content, or merging multiple HTML files. Therefore the description does not accurately represent this code chunk.
The declared description says this skill converts HTML or design inputs into a pixel-faithful PowerPoint and should trigger on HTML uploads requesting PPT conversion. The supplied code does not parse HTML, render designs, or generate slides from HTML. Instead, it takes existing PPTX files, inspects them, and merges slides from multiple PPTX archives into one by copying and rewriting internal Office Open XML parts such as slide XML, relationships, charts, embedded Excel files, media, presentation relationships, and content types. While merging multiple slides into one PPTX could be a supporting step in a larger HTML-to-PPT pipeline, this code chunk’s actual primary function is PPTX-to-PPTX merging, not HTML/design-to-PPT conversion. That is a material description-behavior mismatch.
Without declared permissions the skill's intent is opaque and cannot be validated.
Suspicious Unicode normalization or mixed-script content
The activation text uses very broad trigger phrases such as 'make a PowerPoint' and 'turn this into slides,' and further instructs 'Always follow this skill — never improvise the workflow.' This can cause the skill to capture common user requests too aggressively, forcing file-writing and command-execution workflows in contexts where a simpler or safer response would be more appropriate.
The skill hardcodes font substitutions such as mapping 'PingFang SC' to 'Microsoft YaHei' and other fonts to fixed alternatives without user opt-in. While not directly code-execution risky, this overrides user intent and can silently alter language/script rendering, brand styling, or accessibility characteristics in generated documents.
The example calls pres.writeFile({ fileName: "Presentation.pptx" }), which performs a filesystem write. Although expected in context, the markdown does not explicitly mention that this action creates or may overwrite an output file, so there is no user-facing disclosure about the data-affecting behavior.
This markdown file includes examples that fetch images from https://example.com/..., which implies outbound network access and transmission of request metadata. The tutorial does not warn users that using URL-based image sources or backgrounds may contact external services and affect privacy or reproducibility.
This code unconditionally creates the output directory and writes charts.json to it, which is a file-modifying operation. While the module docstring mentions the output file, there is no inline warning, confirmation, or explicit disclosure at the point of write that the script will create directories and overwrite or replace output content.
This code performs a file write via write_zip(output_path, dest) and defaults the output path to ./final.pptx. While the CLI exposes --out, there is no confirmation prompt or explicit warning comment/docstring near the write path that the script will create or overwrite a local file.
No suspicious patterns detected.