Back to skill

Security audit

revol-presentation-html-generator

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent presentation and article generation skill, with a Chinese-language default and CDN-based slide template that users should understand before using it for sensitive material.

Installers should expect this skill to inspect the project or paper files they ask it to summarize, produce Chinese output by default, and create HTML slide decks that fetch third-party JavaScript and CSS when opened. For confidential or high-assurance presentations, pin exact dependency versions, add integrity checks, or vendor the browser libraries locally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
assets/slide-template.html:8
Finding

Mutable CDN Dependencies Are Loaded Without Subresource Integrity

Content
View full analysis
``` ```html ``` ### Technical Analysis The presentation template loads executable JavaScript and stylesheets directly from jsDelivr. Dependency URLs use mutable major-version selectors such as `@3`, `@4`, and `@10`, rather than exact immutable versions. The resource elements also lack Subresource Integrity (`integrity`) metadata. Consequently, the code executed when a generated presentation is opened is not necessarily identical to the dependency code available when the Skill was audited. A compromised CDN response, upstream package compromise, or malicious release within an accepted major-version range could cause attacker-controlled JavaScript to execute in the presentation's browser context. This is a supply-chain weakness rather than evidence that the current CDN resources are malicious. ### Attack Path 1. A user generates or distributes an HTML presentation based on the supplied template. 2. A viewer opens the presentation while network access is available. 3. The browser retrieves Revea ...[truncated 1192 chars]
Remediation
View remediation
``` 3. Prefer vendoring reviewed dependency files locally when presentations must remain reproducible or operate in sensitive environments. 4. Establish an explicit dependency-update process that includes version review, integrity-hash regeneration, and security testing. 5. Add a restrictive Content Security Policy that permits scripts and styles only from required sources and blocks unnecessary connections. 6. Consider generating fully self-contained presentations so opening a deck does not retrieve executable content from the network. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that all content should be produced in Chinese by default, overriding likely user or system language preferences unless the user notices and corrects it. This can cause unauthorized behavior, reduce usability, and create compliance or accessibility issues in contexts where output language must follow user intent or policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file begins with a Chinese-only article template title, indicating the skill is intended to produce output in Chinese by default. There is no visible opt-in, language selection mechanism, or justification that this must be Chinese-only, which creates a locale/language policy concern under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill guidance is written as a Chinese-only instruction set, including headings, examples, and recommendations, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire prompt template is written as prescriptive Chinese instructions and does not indicate that the user may choose another language or locale. This creates a natural-language policy concern because it implicitly constrains output language without documented user opt-in or a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document title and all instructional content are written in Chinese, presenting the skill guidance in a single language without offering a user language choice. The policy requires flagging language or locale constraints when they are imposed without opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTML declares lang="zh-CN" and the document title/content are written in Chinese, which imposes a specific language/locale in the template by default. There is no visible indication that users may choose another language or that the template is intentionally restricted to a China-specific context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.