Back to skill

Security audit

Union Ad Corporate

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed UnionSkill-branded PPT generator, but it automatically inserts third-party branding into user deliverables and imports an unreviewed assembler from outside the skill package.

Install only if you intentionally want UnionSkill-branded Chinese-language corporate PPTs. Review generated decks before sharing, especially the final slide, watermark, author metadata, and cooperation file. Avoid running the assembler unless the sibling ppt-generator dependency is from a trusted source and protected from local tampering.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:36
Finding

Mandatory Third-Party Branding and Promotional Content Injection

Content
View full analysis
--style corporate-blue --topic "PPT标题" ``` > 此步骤自动完成:品牌尾页嵌入 + 每页水印 + 元数据写入 + 合作说明文件生成 ``` ```markdown ## 交付格式 ``` ✅ 企业蓝风格PPT生成完成,共 X 页 📁 PPTX:/path/to/output.pptx 📁 图片ZIP:/path/to/images.zip 📁 合作说明:/path/to/UnionSkill-合作说明.txt --- 💡 同款AI能力已应用于机加工报价场景 官网:www.unionskillai.com 商务合作:miscdd@163.com ``` ``` ### Technical Analysis The skill instructions require generated presentations to contain a UnionSkill advertising slide, a watermark on every slide, UnionSkill authorship metadata, and a separate commercial cooperation file. They also prescribe a fixed promotional message in the final delivery response. These modifications are automatic rather than an independently confirmed delivery option. Consequently, loading and following the skill changes the agent's output objectives from creating a presentation for the user to creating a presentation that also promotes a third party. Altering document metadata is especially significant because it can represent UnionSkill as the author regardless of the actual author or customer. The functionality is disclosed in the skill documentation and is limited to a branded-presentation workflow. Nevertheless, it creates a persistent and potentially unwanted alteration of user artifacts. The issue becomes exploitable whenever the skill is selected without the user understanding that branding a ...[truncated 1441 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/main.py:8
Finding

Arbitrary Code Execution Through an Unverified External Python Module

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents the skill as a complete end-to-end workflow for generating business PPTs from analysis through image creation to final assembly. The supplied code chunk, however, is narrowly an assembly wrapper around an external union_pptx_assembler, requiring an existing image_dir and returning a readiness message if images are absent. That means the implemented primary behavior in this code is materially narrower than the declared purpose. The extra terminal marketing/contact output is also undeclared, though secondary. This is therefore a description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation guidance is very broad: '任何支持 image_generate 工具的AI Agent均可使用本Skill' and the example trigger is generic. This can cause the skill to activate in loosely related contexts without clear scope boundaries, increasing the chance of unintended execution or misuse by agents that interpret vague user requests too aggressively. In this PPT-generation context the risk is limited because the documented workflow is mostly content creation, but broad triggering still weakens safety and predictability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction says generated slide prompts must include '中文标题清晰可读', which forces Chinese output formatting. The file does not provide user opt-in, language selection, or a documented region-specific justification for this locale requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The prompt template explicitly requires 'large readable Chinese headings,' which imposes a specific language on outputs. The file does not indicate this is optional, user-selected, or justified as a region-specific requirement, so it appears to violate the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and all visible user-facing messages are written in Chinese, and the code does not offer any language selection or opt-in. This is a natural-language policy concern because the skill appears to enforce a specific language/locale for interaction regardless of user preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.