Back to skill

Security audit

agy-ppt

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed presentation-generation workflow, but one image-artifact path handling flaw can copy unintended local image files into a project output.

Review before installing. The core workflow is coherent, but the image adapter should be fixed to resolve and require reported artifacts to live under the current generated_images/thread directory before copying. Until then, avoid running it on untrusted slide/source prompts or in an environment with sensitive local screenshots, scans, or diagrams readable by the process.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/codex_image_adapter.py:747
Finding

Worker-reported artifact path permits copying arbitrary readable local images

Content
View full analysis

Vulnerability Details

File Location: scripts/codex_image_adapter.py, lines 747–753 and 1018–1028
Vulnerability Type: Improper path authorization / arbitrary local image disclosure
Risk Level: Medium

Vulnerable Code

python
candidate = Path(os.path.expanduser(cleaned))
if not candidate.is_absolute():
    candidate = images_root / cleaned
candidate = Path(os.path.normpath(str(candidate)))
if candidate.is_file() and candidate.suffix.lower() in ALLOWED_IMAGE_SUFFIXES:
    return ArtifactDiscovery(candidate, "explicit_reported_path", [str(candidate)])

The accepted source is subsequently copied into the workspace:

python
fd, tmp_name = tempfile.mkstemp(dir=str(target.parent), suffix=target.suffix)
os.close(fd)
tmp_path = Path(tmp_name)
try:
    shutil.copyfile(source, tmp_path)
    os.replace(tmp_path, target)
finally:
    if tmp_path.exists():
        try:
            tmp_path.unlink()
        except OSError:  # pragma: no cover - defensive
            pass

Technical Analysis

discover_artifact() treats paths extracted from Codex-generated agent text as artifact candidates. If a reported path is absolute, the adapter uses it directly. Acceptance requires only that the path identify an existing file with an allowed image suffix.

Although the function documentation states that an explicitly reported artifact must live under $CODEX_HOME/generated_images, the explicit-path branch does not enforce that containment requirement. It applies lexical normalization with normpath(), but does not resolve the path and verify that it remains beneath the trusted image-generation directory.

The accepted path is later passed to shutil.copyfile(), which reads the selected local file and places a copy at the user-authorized workspace output path. This turns worker-controlled text into a local file-selection capability.

The normal output-path validation protects the desti ...[truncated 2044 chars]

Remediation
View remediation

Remediation Suggestions

  1. Canonicalize both the generated-images root and the reported candidate using Path.resolve(strict=True).
  2. Reject the candidate unless it is a regular file beneath the canonical $CODEX_HOME/generated_images directory.
  3. When a Codex thread ID is available, narrow authorization further by requiring the artifact to reside beneath that thread’s generated-image directory.
  4. Reject symbolic links, or open the source with platform-appropriate no-follow semantics and verify the opened file’s identity before copying.
  5. Repeat the containment and file-type checks immediately before the copy to reduce time-of-check/time-of-use risk.
  6. Prefer selecting artifacts from a before/after filesystem snapshot rather than trusting paths reported in model-generated text.
  7. Add regression tests covering absolute paths outside the generated-images root, .. traversal, symlink escapes, and paths belonging to a different thread.

Example containment logic:

python
trusted_root = images_root.resolve(strict=True)
candidate = candidate.resolve(strict=True)

if not candidate.is_file() or candidate.suffix.lower() not in ALLOWED_IMAGE_SUFFIXES:
    continue

try:
    candidate.relative_to(trusted_root)
except ValueError:
    continue
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (282)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a slide/image workflow, yet it also includes a substantial local document ingestion pipeline for PDF/Markdown/TXT/DOCX/HTML. That broader capability is real in the text and expands the attack surface to local document parsing and filesystem output, which should be explicitly surfaced as a separate trust domain.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification, suspicious.obfuscated_code

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
tests/test_source_acquisition.py:842

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
tests/helpers/synthetic_docx.py:141