Back to skill

Security audit

About `html-to-one-pptx` is a Claude Code Skill that automates the entire pipeline from an HTML design file to a `.pptx` slide.

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local HTML-to-PowerPoint workflow with helper scripts, but users should be aware it writes files, runs local Python/Node code, and has some dependency and parser hardening gaps.

Install and run this only in a project or virtual environment, avoid global npm installs when possible, do not process PPTX files from untrusted sources with the merge helper, and review output paths because the workflow creates local tmp files and PPTX outputs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/merge_slides.py:56
Finding

Unhardened XML Parsing of User-Controlled PPTX Content

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
pptxgenjs.md:238
Finding

Unpinned and Global Third-Party Dependency Installation Instructions

Content
View full analysis
Remediation
View remediation
react@ react-dom@ sharp@ ``` ```bash python -m pip install \ python-pptx== \ lxml== ``` 2. Commit `package-lock.json` or an equivalent lockfile containing integrity metadata. 3. For Python, provide a locked requirements file generated by a tool such as `pip-compile`, preferably with hashes: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Install Node.js packages locally to the project rather than with `npm install -g`. 5. Install Python packages inside a dedicated virtual environment. 6. Document the expected package registry and avoid unreviewed mirrors. 7. Review transitive dependencies and installation scripts before version upgrades. 8. Use automated dependency scanning and controlled update procedures. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises an end-to-end, pixel-faithful HTML/design to PowerPoint conversion workflow. The supplied code chunk is only a chart-detection helper script. Its scope is limited to extracting chart-related information from one HTML file and optional intermediate files (layout_map.json, svg_inventory.json, design_spec.json), then generating pptxgenjs snippets and charts.json. This is a materially narrower and different purpose than full PPT conversion. While chart extraction could be a supporting component within such a pipeline, the code itself does not implement the declared primary capability of producing PPT slides, handling arbitrary page content, or merging multiple HTML files. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill converts HTML or design inputs into a pixel-faithful PowerPoint and should trigger on HTML uploads requesting PPT conversion. The supplied code does not parse HTML, render designs, or generate slides from HTML. Instead, it takes existing PPTX files, inspects them, and merges slides from multiple PPTX archives into one by copying and rewriting internal Office Open XML parts such as slide XML, relationships, charts, embedded Excel files, media, presentation relationships, and content types. While merging multiple slides into one PPTX could be a supporting step in a larger HTML-to-PPT pipeline, this code chunk’s actual primary function is PPTX-to-PPTX merging, not HTML/design-to-PPT conversion. That is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation text uses very broad trigger phrases such as 'make a PowerPoint' and 'turn this into slides,' and further instructs 'Always follow this skill — never improvise the workflow.' This can cause the skill to capture common user requests too aggressively, forcing file-writing and command-execution workflows in contexts where a simpler or safer response would be more appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill hardcodes font substitutions such as mapping 'PingFang SC' to 'Microsoft YaHei' and other fonts to fixed alternatives without user opt-in. While not directly code-execution risky, this overrides user intent and can silently alter language/script rendering, brand styling, or accessibility characteristics in generated documents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The example calls pres.writeFile({ fileName: "Presentation.pptx" }), which performs a filesystem write. Although expected in context, the markdown does not explicitly mention that this action creates or may overwrite an output file, so there is no user-facing disclosure about the data-affecting behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file includes examples that fetch images from https://example.com/..., which implies outbound network access and transmission of request metadata. The tutorial does not warn users that using URL-based image sources or backgrounds may contact external services and affect privacy or reproducibility.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code unconditionally creates the output directory and writes charts.json to it, which is a file-modifying operation. While the module docstring mentions the output file, there is no inline warning, confirmation, or explicit disclosure at the point of write that the script will create directories and overwrite or replace output content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code performs a file write via write_zip(output_path, dest) and defaults the output path to ./final.pptx. While the CLI exposes --out, there is no confirmation prompt or explicit warning comment/docstring near the write path that the script will create or overwrite a local file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.