Back to skill

Security audit

Slidev Assist

Security checks for vulnerabilities and agentic risk

Overview

This skill is for making Slidev presentations, but it broadly processes files and web content while recommending automatic, unpinned npm/npx execution, so it needs user review before installation.

Review this skill before installing. Use it only in a workspace where npm package installation and local file processing are acceptable, avoid sensitive documents unless you are comfortable with the agent reading them, pin Slidev and Playwright versions with a lockfile, avoid global installs, and do not enable --remote unless you understand the network exposure.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/init-slidev.sh:19
Finding

Unpinned npm dependencies are downloaded and executed

Content
View full analysis
/dev/null 2>&1; then echo "📥 安装 Slidev..." npm install @slidev/cli > /dev/null 2>&1 fi ``` `SKILL.md:99-100`: ```bash npm install slidev-theme-xxx ``` `SKILL.md:327-335`: ```bash npx slidev export slides.md npx slidev export slides.md --format pptx npx slidev export slides.md --format png ``` `SKILL.md:357-389`: ```bash npx --yes @slidev/cli --version 2>/dev/null test -d node_modules && npm ls @slidev/cli 2>/dev/null cd 项目目录 npm install @slidev/cli npm install -g @slidev/cli npm init slidev npm install -D playwright-chromium ``` `SKILL.md:394-405`: ```bash echo '{"name":"ppt","private":true}' > package.json npm install @slidev/cli npm install -D playwright-chromium npx @slidev/cli slides.md --remote ``` `references/quickref.md:13-23`: ```bash npm init slidev npx @slidev/cli slides.md npx @slidev/cli slides.md --remote npx @slidev/cli export slides.md npx @slidev/cli export slides.md --format pptx ``` ### Technical Analysis The project installs and executes npm packages without specifying reviewed, exact versions or enforcing a lockfile. Commands such as `npm install @slidev/cli`, `npm init slidev`, and `npx @slidev/cli` resolve packages from the configured npm registry at execution time. Consequently, the code executed during a future skill invocation can differ from the code that was available when the skill itself was audited. npm installations may execute package lifecycle scripts with the privileges of the user running the skill. The generic instruction to install `slidev-theme-xxx` also permits selection of arbitrary community packages without an ...[truncated 2743 chars]
Remediation
View remediation
npm install --save-dev --save-exact playwright-chromium@ ``` 2. Commit a reviewed `package-lock.json` and use deterministic installation: ```bash npm ci ``` 3. Configure CI to reject lockfile drift and verify that `package.json` and `package-lock.json` remain synchronized. 4. Replace all ambiguous `npx slidev` examples with the reviewed `@slidev/cli` package. Prefer local binaries installed from the lockfile: ```bash npm exec --offline -- @slidev/cli slides.md ``` 5. Avoid `npm init slidev` and unpinned `npx` execution in automated workflows. If temporary execution is unavoidable, specify an exact reviewed version and require explicit user approval before downloading it. 6. Maintain an allowlist of reviewed Slidev themes with exact versions. Do not automatically install arbitrary package names supplied through presentation content or untrusted user material. 7. Review dependency lifecycle scripts and package provenance before installation. Where compatible with the required packages, consider initially installing with lifecycle scripts disabled: ```bash npm ci --ignore-scripts ``` Only run specifically required and reviewed setup steps afterward. 8. Remove the global installation recommendation because global packages increase the affected scope and are harder to reproduce or audit. 9. Require explicit user confirmation before enabling `--remote`. Bind preview services to localhost by default and document any firewall, authentication, and trusted-network requirements. 10. Do not suppress all npm output in the initialization script. Preserve installation errors and security-relevant package information so users and automated monitoring can detect unexpected package behavior. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个端到端的内容生成与幻灯片导出能力:接收多种原材料,AI 解析后生成 Markdown,并进一步调用 Slidev 产出 HTML 幻灯片。实际代码只是一个环境初始化脚本,用于准备 Slidev 运行环境:创建 package.json、安装 @slidev/cli,并提示用户后续手动执行命令。它没有读取或解析任何原材料文件,没有生成 slides.md 内容,也没有执行 Slidev 构建/导出。因此其主要目的与声明存在实质性偏差。

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The README instructs use of npx slidev without pinning a version, which allows the latest package version to be resolved at execution time. That creates a supply-chain and reproducibility risk: a malicious or compromised upstream release could be fetched and executed unexpectedly when the skill runs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation examples are very broad and map ordinary user requests directly into automated file parsing, content fetching, and command execution flows. In an agent setting, unclear trigger boundaries increase the chance of unintended activation on ambiguous prompts, which can lead to unauthorized processing of local files or external content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises fetching web content and processing user-provided local files into generated outputs, but provides no warning about data handling, privacy, or trust boundaries. This can cause users to expose sensitive documents, URLs, or embedded secrets to the agent and downstream tools without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill uses very broad trigger language like accepting 'any raw material' and handling common tasks such as reports, data, documents, and PPTX files. Broad activation scope can cause the skill to engage in many ordinary contexts and then proceed to read files and run local commands, increasing the chance of unintended or insufficiently consented execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Early in the skill, the workflow promises automatic installation and startup of Slidev without an explicit up-front warning that local packages may be installed and commands executed. In agent settings, lack of conspicuous consent language is dangerous because users may believe they are only asking for content transformation, not permitting environment changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs use of npx slidev export slides.md without pinning a specific package version. Unpinned npx execution can fetch and run whatever version is current at execution time, which creates a supply-chain risk and undermines reproducibility; if the upstream package or dependency chain is compromised, arbitrary code may run on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This export command again relies on unpinned npx slidev, causing the tool to resolve to an unspecified version at runtime. In a skill that explicitly installs and runs local tooling, that materially increases supply-chain exposure because the agent may trigger code execution from the network in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The PNG export example uses the same unpinned npx slidev pattern. Because this skill is designed to take arbitrary user materials and then install/run a CLI, unpinned package execution is more dangerous than in a purely informational document: it normalizes immediate execution of mutable third-party code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

npx --yes @slidev/cli --version both auto-confirms execution and does not pin a version, so even a 'version check' may download and run a remote package. That means a seemingly harmless detection step can execute arbitrary package lifecycle code from the network on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The text explicitly recommends npx @slidev/cli auto-download behavior without version pinning. This encourages the agent or user to execute remote package code opportunistically, which is a classic supply-chain hazard and can lead to arbitrary command execution if the package or one of its dependencies is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The preview command npx @slidev/cli slides.md --remote is another unpinned remote execution path. The --remote flag also exposes additional runtime behavior, so combining remote-control functionality with unpinned package execution increases the attack surface in the user's local environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description claims it accepts essentially any topic or source material, including reports, data, copy, and PPTX files, which creates an overly broad activation and trust boundary. In an agent ecosystem, this can cause the skill to trigger on unintended inputs and encourage processing of untrusted documents without clearly scoped limits, increasing the chance of misuse, unsafe file handling, or prompt/content injection through supplied materials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The only natural-language description is written in Chinese, which effectively imposes a specific language/locale presentation without any indication that users may choose another language. The policy requires avoiding forced language constraints unless the file explicitly offers user opt-in or documents a justified regional limitation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file contains comments and user-visible messages only in Chinese, which imposes a specific language without user opt-in. Per the policy, language constraints should either be optional, user-selectable, or clearly justified.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The script tells the user to run npx @slidev/cli without a pinned version, which can fetch or resolve whatever package version is current at execution time. In a build/bootstrap script for presentation generation, this creates supply-chain and reproducibility risk because future or compromised releases could change behavior or execute unexpected code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Natural-language instructions and examples throughout the file assume Chinese as the only interaction language. Under the stated policy, forcing a specific language without user opt-in or a documented regional justification is a locale-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template includes user-facing text in Chinese such as the title placeholder example and the continuation prompt, with no indication that the skill supports other languages or that this template is intended only for a Chinese-speaking audience. This can violate the language/locale policy because it imposes a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown template uses Chinese-language placeholders throughout, such as the title, subtitle, section headings, and content labels. Because the file provides no indication that it is intended only for Chinese-language users or that other languages are acceptable, it can be interpreted as enforcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The template sets the title to Chinese text ("演示标题"), which may implicitly impose a specific language/locale in generated content. There is no accompanying note indicating that this template is region-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains user-facing guidance almost entirely in Chinese, including headings and descriptive text, but does not indicate that the skill is intended specifically for Chinese-speaking users or provide an opt-in language choice. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.