Back to skill

Security audit

PPT Ultra-wide Relayout

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent PowerPoint relayout helper with no hidden persistence, network access, or credential handling, though users should only process trusted PPTX files due to XML/ZIP parsing hardening gaps.

Install only if you are comfortable using it on PPTX files you trust or in a sandboxed environment. It writes a derived PPTX to the output path you provide, so choose a new filename to avoid overwriting work. Avoid running it on decks from unknown senders until XML parser and ZIP size-limit hardening are added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/pptx_layout_dump.py:20
Finding

Unsafe XML Parsing of Untrusted PPTX Content in Layout Analyzer

Content
View full analysis
etree._Element: parser = etree.XMLParser(remove_blank_text=False, recover=True) return etree.fromstring(blob, parser=parser) ``` ### Technical Analysis PPTX documents are ZIP archives containing XML documents controlled by the file provider. The layout analyzer passes those XML documents to `lxml.etree.XMLParser` without explicitly disabling DTD loading and entity resolution. The parser also enables recovery mode. This causes malformed, potentially malicious XML to be processed where strict parsing would otherwise reject it. Security consequently depends on the behavior and version-specific defaults of the installed `lxml` and `libxml2` libraries. If entity expansion or external entity processing is available in the runtime configuration, a crafted PPTX may attempt to reference local files or cause excessive entity expansion. Extracted XML text is subsequently included in the generated JSON report, creating a potential path for resolved local-file content to reach command output. The script also reads ZIP members directly without checking their declared or actual uncompressed sizes. A malicious PPTX containing highly compressed or extremely large XML members can therefore cause excessive memory or CPU consumption. ### Attack Path 1. An attacker creates a PPTX archive containing a malicious `ppt/presentation.xml`, theme XML, or slide XML. 2. The attacker provides the file as the source deck for layout analysis. 3. The script opens the archive and reads the attacker-controlled XML member into memory without applying size limits. 4. `parse_xml` processes the content with recovery enabled and without explicit DTD and entity restrictions. 5. Depending on the installed parser configuration, malicious entities ...[truncated 891 chars]
Remediation
View remediation
etree._Element: if b"

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/pptx_ultrawide_relayout.py:18
Finding

Unsafe XML Parsing of Untrusted PPTX Content in Relayout Processor

Content
View full analysis
etree._Element: parser = etree.XMLParser(remove_blank_text=False, recover=True) return etree.fromstring(blob, parser=parser) ``` ### Technical Analysis Both the source and reference PPTX files are untrusted ZIP containers. Their presentation and slide XML members are parsed without explicitly disabling DTD loading and entity resolution. Recovery mode is enabled, allowing malformed input to be processed instead of being rejected strictly. This leaves parser security dependent on the installed `lxml` and `libxml2` defaults. In an environment where entity processing is available, malicious XML may attempt local-file references or entity-expansion attacks. Because transformed XML is serialized into the output PPTX, resolved content could potentially be propagated into the generated document. The processor also reads source and reference ZIP members into memory without entry-count, uncompressed-size, aggregate-size, or compression-ratio limits. Crafted source or reference decks may consequently trigger excessive memory and CPU consumption. ### Attack Path 1. An attacker constructs a malicious source or reference PPTX containing crafted presentation or slide XML. 2. A user invokes the relayout processor with the malicious file. 3. The processor reads the XML members from the ZIP archive without resource limits. 4. The XML is parsed with recovery enabled and without explicit DTD or entity restrictions. 5. Depending on runtime parser behavior, entity expansion may consume resources or an external entity may reference a file readable by the process. 6. Parsed content is transformed and serialized into the output PPTX, potentially carrying resolved data into that output. An oversized or highly compressed mem ...[truncated 592 chars]
Remediation
View remediation
etree._Element: if b"
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个主动执行 PPT 版式重排/宽屏适配的技能,核心能力应包括读取现有 PPT、计算新页面比例下的元素布局,并修改或生成重排后的演示文稿。实际代码仅做静态解析与信息提取:从 presentation.xml 获取页面尺寸,从 theme1.xml 获取主题颜色和字体,再遍历各页 shape 提取位置、比例、文本、字号、字族和填充色,最后以 JSON 打印结果。虽然这些信息可能可作为后续重排的辅助输入,但当前代码本身没有任何重排、缩放、编辑、写回 PPTX、参考另一份 PPT 比例/视觉语言的逻辑,因此与声明的主要用途存在实质性不符。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill uses broad proactive trigger phrases like '只要用户提到…就应该主动使用这个 skill', which can cause over-invocation on loosely related requests. In an agent environment, ambiguous auto-selection increases the chance of unnecessary file processing or unintended modification workflows being initiated without sufficiently confirming user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire reference document is written in Chinese and provides no indication that other languages are supported or that the user can choose a locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file is primarily in English, but lines 5 through 9 switch to Chinese for outreach and contact instructions. This creates a language/locale constraint in natural-language content without user opt-in or a bilingual alternative, which matches the policy's language-choice concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill instructs producing a new PPTX output file but does not tell the agent to warn the user that files will be created or modified. In practice this can lead to surprising state changes, overwriting expectations, or silent generation of derived documents from user-provided content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code includes a hard-coded Chinese error message in a script whose other user-facing CLI strings are in English, creating a fixed locale behavior without user opt-in or documented justification. The policy for natural-language content requires offering language choice or clearly documenting locale constraints when a specific language is enforced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code raises user-visible exceptions in Chinese (presentation.xml 中未找到 p:sldSz) while the rest of the CLI interface is in English. That creates a mixed-language experience and imposes a locale choice without explicit user opt-in or documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.