Back to skill

Security audit

Union Ad Chinese

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-style UnionSkill advertising PPT generator, but it requires non-optional branding and runs an out-of-package Python assembler that was not included for review.

Install this only if you intentionally want UnionSkill-branded Chinese-style advertising presentations. Review outputs for watermarks, the added UnionSkill closing slide, author metadata, and contact information before sharing them. Do not use it for unbranded corporate, government, or client deliverables unless the branding is acceptable, and audit or bundle the referenced ppt-generator assembler before running the Python entry point.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/main.py:29
Finding

Mandatory Third-Party Advertising and Output Manipulation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:8
Finding

Execution of an Unverified Python Module Outside the Audited Package

Content
View full analysis
--style chinese-traditional --topic "PPT标题" ``` ### Technical Analysis The entry point prepends a relative directory outside the audited project to `sys.path` and imports `union_pptx_assembler` from that location. Python executes module-level code as soon as the import occurs. The security behavior of this Skill therefore depends on an external, mutable Python file that was not present in the audited project. Because the inserted directory receives the highest module-search priority, any file named `union_pptx_assembler.py` at that resolved location can be loaded. There is no path canonicalization, ownership check, signature validation, hash verification, or package-version constraint. The documentation also references a different home-directory path. This discrepancy can make it difficult to determine which assembler is trusted and can lead to environment-dependent behavior. ### Attack Path 1. An attacker gains write access to the external `ppt-generator/scripts` directory or influences how the project is installed relative to that directory. 2. The attacker creates or replaces `union_pptx_assembler.py`. 3. The user or Agent imports or executes `scripts/main.py`. 4. Python searches the prepended external directory and imports the attacker's module. 5. Malicious module-level code executes immediately, ...[truncated 793 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
README.md:27
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README presents the skill as specifically 'Chinese style' and the description is written entirely in Chinese, with no indication that users can opt into another language or locale. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction says generated image prompts 'must' include Chinese-specific styling and that Chinese titles must be clearly readable. This imposes a language/locale constraint in the skill behavior without any opt-in or alternative for users who may want another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes the instruction "large readable Chinese headings," which imposes a specific language output requirement. Under the policy, forcing a language without user opt-in or a clearly documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file defines the skill as specifically "chinese-traditional" and presents Chinese-language branding/output with no indication that users can opt into another language or locale. Under the policy rules, forcing a specific language/locale without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.