Back to skill

Security audit

Antfu Slidev

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Slidev documentation skill with expected setup, export, editor, and remote-asset features, but users should treat package installs, runnable code, and remote URLs with normal development caution.

Install or use this skill as normal Slidev guidance, but run package installation and export commands in a project workspace without unnecessary secrets, prefer pinned package versions or a lockfile, and only use runnable code, writable Monaco examples, embeds, and remote URLs from sources you trust.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Slidev Package Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 20
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Complete Code Snippet:

bash
pnpm create slidev    # Create project

Technical Analysis

The documented command resolves a package through the user's configured package registry without specifying a vetted version or integrity constraint. Project-creation packages execute code locally as part of initialization, so the effective code can change after this Skill has been audited.

This creates a supply-chain exposure if the package, publisher account, registry, or local registry configuration is compromised. The audit found no evidence that the Skill's author intentionally supplies a malicious package; the issue is the unsafe, mutable dependency resolution process.

Attack Path

  1. An attacker compromises the relevant package publication channel or causes the user to resolve packages through a malicious registry.
  2. The attacker publishes or serves a modified package version containing malicious initialization or lifecycle code.
  3. A user follows the Skill and runs pnpm create slidev.
  4. pnpm retrieves the currently resolved, unpinned package.
  5. The package code executes with the permissions and environment of the invoking user.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the invoking user's account. The accessible scope may include the presentation project, other files writable by that user, environment variables exposed to the process, available developer credentials, and network resources reachable from the host. This command does not itself request elevated privileges, so system-wide or administrative access would require the user to run it with such privileges or the attacker to exploit an additional privilege-escalation flaw.

Remediation
View remediation

Remediation Suggestions

  • Specify an explicitly vetted Slidev initializer version rather than resolving the latest available version.
  • Use the expected official registry explicitly in controlled environments.
  • Review the selected package version, its publisher, provenance, and lifecycle scripts before execution.
  • Generate and commit a lockfile containing integrity metadata for the resulting project.
  • Enforce lockfile-based, immutable installation in CI.
  • Run project initialization as an unprivileged user in an isolated workspace without unnecessary secrets in the environment.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:112
Finding

Unpinned Playwright Chromium Development Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 112
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Complete Code Snippet:

bash
**Export prerequisite**: `pnpm add -D playwright-chromium` is required for PDF/PPTX/PNG export. If export fails with a browser error, install this dependency first.

Technical Analysis

The instruction installs playwright-chromium without a fixed version or an independently enforced integrity value. Consequently, the installed content depends on the registry response at installation time and may differ from the version that was available when the Skill was reviewed.

Package installation can invoke lifecycle scripts and download supporting browser components. A compromised package release, publisher account, registry, or registry configuration could therefore convert this documented installation step into local code execution. No malicious dependency content is included in the audited project itself; the finding concerns unsafe dependency acquisition.

Attack Path

  1. An attacker compromises the package publication channel or influences the user's registry resolution.
  2. A malicious or altered playwright-chromium release is made available.
  3. The user encounters an export-related browser error and follows the instruction to run pnpm add -D playwright-chromium.
  4. pnpm resolves and downloads the mutable, unpinned dependency.
  5. Malicious package or lifecycle code executes during installation or subsequent export operations.

Impact Assessment

Exploitation could execute arbitrary code with the invoking user's privileges. Potentially exposed assets include the current project, user-writable files, process environment variables, package-manager credentials, developer tokens, and network-accessible services. The documented instruction does not require administrative privileges, so its direct scope is normally limited to ...[truncated 104 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin playwright-chromium to a specifically reviewed version.
  • Commit the generated lockfile and preserve its package integrity metadata.
  • Use frozen or immutable lockfile installation in development automation and CI.
  • Verify package provenance, publisher identity, registry origin, and lifecycle scripts.
  • Perform installation and export in a sandboxed, unprivileged environment with minimal filesystem and network access.
  • Avoid exposing unrelated credentials or secrets to package installation and export processes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly advertises monaco-run and monaco-write features, which enable code execution and file modification, but provides no warning that these capabilities can execute untrusted code or alter local files. In an agent skill context, omission of safety guidance increases the chance that a user or downstream system invokes these features on attacker-controlled content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill notes automatic caching of remote URLs/assets without disclosing that this triggers outbound network requests and may expose IP address, metadata, or fetch untrusted remote content. In a presentation tool, this is expected functionality, but the lack of privacy/network warning can still lead to unintended data exposure or policy violations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.