Back to skill

Security audit

Ppt Agent

Security checks for vulnerabilities and agentic risk

Overview

This PPT-to-SVG skill is mostly coherent, but its optional SVG generator can turn untrusted JSON into active SVG files without sanitizing the content.

Install only if you are comfortable with a Chinese-focused PPT/SVG workflow and treat the optional JSON-to-SVG script as trusted-input only. Do not feed it JSON from other people or unknown sources, and be cautious opening generated SVG files in browsers or other viewers that may execute active SVG features.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_svg.py:261
Finding

Untrusted JSON Content Is Embedded Verbatim into Generated SVG Files

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_svg.py, lines 261–267 and 285–289
Vulnerability Type: Active SVG/XML markup injection
Risk Level: High

Vulnerable Code

python
def make_svg(body_content: str) -> str:
    """Wrap content in complete SVG document."""
    return f'''<?xml version="1.0" encoding="UTF-8"?>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 1280 720">
  <rect width="1280" height="720" fill="#FFFFFF"/>
{body_content}
</svg>'''
python
pages = data.get('pages', [])
for i, page in enumerate(pages, 1):
    content = page.get('content', '')
    out_path = output_dir / f'page_{i:02d}.svg'
    out_path.write_text(make_svg(content), encoding='utf-8')

Technical Analysis

The script reads pages[].content from an arbitrary JSON input file and interpolates it directly into an SVG document without parsing, validation, sanitization, or escaping.

Although the module provides escape_svg() for text passed through its slide-building helpers, the main generation path does not use those helpers. Instead, it treats the entire content field as trusted SVG markup. Consequently, an attacker can insert arbitrary SVG/XML elements and attributes, including:

  • <script> elements
  • Event handlers such as onload or onclick
  • External resource references through href
  • Interactive links
  • <foreignObject> containing active HTML
  • Other SVG features with behavior dependent on the consuming application

This is an active-content injection issue rather than ordinary text injection. The generated artifact cannot be considered a passive presentation file when its input is untrusted.

Attack Path

  1. An attacker creates or modifies the JSON file supplied to generate_svg.py.

  2. The attacker places active SVG/XML markup in a pages[].content value.

  3. A user runs:

    text
    generate_svg.py <input.json> <output_dir>
    
  4. The script loads the attacker-controlled value and passes it unchanged to ...[truncated 1391 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace raw SVG input with a structured schema. Define allowed page types, text fields, dimensions, colors, and layout options. Generate all SVG elements internally rather than accepting an arbitrary markup string.

  2. Escape all untrusted text and attribute values. Route text through escape_svg() and validate values used in XML attributes. Escaping text alone is insufficient if users can control complete tags or attributes.

  3. Apply strict allowlist sanitization if raw SVG support is required. Parse the content with a hardened XML parser and retain only explicitly approved presentation elements and attributes.

  4. Reject active or externally connected features, including:

    • script
    • foreignObject
    • Event attributes beginning with on
    • External href or xlink:href values
    • Remote images, stylesheets, and fonts
    • Unsafe namespace declarations
    • Animation or event features capable of triggering active behavior
  5. Reject malformed or unexpected input types. Verify that pages is a list, each page is an object, and every permitted property has the expected type, range, and maximum length.

  6. Add regression tests using payloads containing <script>, onload, external href, and <foreignObject>. Tests should verify that these constructs are rejected or rendered as inert text.

  7. Document the trust boundary. Until sanitization is implemented, warn users not to process JSON files from untrusted sources and not to open generated SVG files in browser contexts.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior presents this as an end-to-end PPT-generation agent, but the implementation reportedly only performs lower-level SVG rendering from prebuilt JSON/content. This mismatch is security-relevant because users and orchestrators may grant trust, permissions, or autonomy based on capabilities the skill does not actually implement, increasing the chance of unsafe fallback behavior or misuse of other tools to fill the gap.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill references local prompt files and a script, implying file read/write capabilities, but it does not declare any explicit tool scope or permissions boundary. This can lead to overbroad agent access at runtime, making unintended file operations harder to constrain or audit if the platform auto-grants filesystem access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are very broad and can match many generic presentation or document-related requests. Overbroad activation increases the chance the skill is invoked in contexts where it should not run, potentially causing unintended file access, unexpected content generation, or workflow hijacking over more appropriate skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file specifies Chinese font handling in the output format and the overall instructions are written solely around Chinese-language PPT generation, but there is no explicit user opt-in or alternative locale path. This may violate language/locale policy if the organization requires offering language choice unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt specifies Chinese fonts and the document consistently requires Chinese text behavior, including a Chinese-specific wrapping function reference. This imposes a language/locale constraint on the skill without any user opt-in or explanation that the skill is intended only for a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill instruction set is written to operate in Chinese, including role, constraints, examples, and confirmation flow, with no indication that the user may choose another language. This creates a natural-language locale policy issue because it implicitly forces a specific language rather than offering a language choice or documenting a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire prompt is written as mandatory Chinese-language instructions and provides no indication that the user may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill content and usage instruction are written only in Chinese, with no indication that the user can choose another language or that the skill is intentionally restricted to a Chinese-language context. Under the policy, a locale or language constraint should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.