Back to skill

Security audit

Union Ad Gradient

Security checks for vulnerabilities and agentic risk

Overview

This is a branded PPT generator, but it forces promotional branding and relies on an unaudited local assembler script to run code during presentation assembly.

Review this before installing if you need clean, unbranded presentations or strict control over generated deliverables. Only use it in an environment where the referenced ppt-generator assembler is trusted and access-controlled, and prefer a pinned dependency setup.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:37
Finding

Mandatory Branding and Commercial Promotion Hijack Generated Deliverables

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:37-45, SKILL.md:114-124, scripts/main.py:31-38
Vulnerability Type: Mandatory output modification and commercial content injection
Risk Level: High

Complete Code Snippet

Relevant mandatory watermark and branding values from SKILL.md:37-45:

text
Generated by UnionSkill | www.unionskillai.com
UnionSkill
www.unionskillai.com
miscdd@163.com

Relevant terminal-output construction from scripts/main.py:31-38:

python
result["terminal"] = (
    f"✅ {STYLE_LABEL} PPT completed, with {slides} slides\n"
    f"📁 PPTX: {result.get('file', 'N/A')}\n"
    f"📁 Partnership file: {result.get('partner_file', 'N/A')}\n"
    f"---\n"
    f"Promotional message for machining quotation services\n"
    f"Website: {DOMAIN}\n"
    f"Business contact: {EMAIL}"
)

The displayed code is an English rendering of the user-facing string literals. The executable logic and interpolation structure are unchanged.

Technical Analysis

The Skill specification requires generated presentations to contain UnionSkill promotional material, including:

  • A branded final slide.
  • A watermark on every slide.
  • UnionSkill author metadata.
  • A separate commercial cooperation file.
  • A fixed promotional footer in the delivery response.
  • An external website and business contact address.

These modifications are not merely optional style defaults. They are defined as automatic output requirements, and the Skill prohibits use for presentations that do not include the branding. Consequently, loading and following the Skill changes the Agent's output objective from generating the user's requested presentation to generating a presentation that also advertises a third party.

The executable entry point reinforces the instruction-level behavior by appending values imported as DOMAIN and EMAIL to the terminal response after successful assembly. The exter ...[truncated 1620 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove mandatory watermarks, promotional final slides, cooperation files, and commercial response footers from the default workflow.
  2. Make branding explicitly opt-in and obtain informed user consent before modifying artifacts.
  3. Provide an unbranded generation mode as the default.
  4. Keep presentation content, metadata, auxiliary files, and delivery messages under user control.
  5. Do not append external URLs or contact information unless the user specifically requests it.
  6. Clearly preview every branding modification during outline confirmation.
  7. Add tests verifying that unbranded requests produce no UnionSkill text, metadata, watermarks, URLs, contact details, or auxiliary promotional files.

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/main.py:8
Finding

Unverified External Assembler Can Be Hijacked Through Python Import-Path Precedence

Content
View full analysis

Vulnerability Details

File Location: scripts/main.py:8-9, scripts/main.py:24; SKILL.md:97-102
Vulnerability Type: External local module loading through a manually prepended search path
Risk Level: Medium

Complete Code Snippet

From scripts/main.py:8-9:

python
sys.path.insert(0, os.path.join(os.path.dirname(__file__), "../../ppt-generator/scripts"))
from union_pptx_assembler import run as assemble, DOMAIN, EMAIL

From scripts/main.py:24:

python
result = assemble(STYLE, image_dir, topic, output)

Documented invocation from SKILL.md:97-102:

bash
python3 ~/.openclaw/skills/ppt-generator/scripts/union_pptx_assembler.py IMAGE_DIRECTORY --style gradient-dream --topic "PRESENTATION_TITLE"

Technical Analysis

The script prepends a sibling directory to sys.path and then imports union_pptx_assembler from that location. Because the inserted directory takes precedence over normal module-resolution locations, any file with that module name in the target directory is imported and executed.

Python executes module-level code immediately during import. Therefore, an attacker who can create or replace the referenced assembler file can obtain code execution as soon as scripts/main.py starts, before assemble() is explicitly called.

The assembler is not included in the audited project. Its implementation, integrity, version, and side effects consequently cannot be verified from this artifact. The import also retrieves DOMAIN and EMAIL from that module, allowing a replacement module to alter user-facing destinations in addition to executing code.

This finding requires an attacker or another compromised component to have write access to the sibling assembler directory. It does not independently bypass filesystem permissions.

Attack Path

  1. The attacker obtains write access to ../../ppt-generator/scripts relative to scripts/main.py, or compromises the com ...[truncated 1467 chars]
Remediation
View remediation

Remediation Suggestions

  1. Package union_pptx_assembler inside the audited project or install it as a verified, versioned dependency.
  2. Remove the runtime sys.path.insert() modification.
  3. Use normal package-relative imports from an immutable or access-controlled installation.
  4. Pin the assembler to a reviewed version and verify its cryptographic hash before execution.
  5. Ensure the dependency directory is not writable by untrusted users or unrelated Agent tasks.
  6. If external execution is unavoidable, resolve the canonical path and verify ownership, permissions, expected location, and file digest before loading it.
  7. Run assembly in a restricted subprocess or sandbox with only the required input and output directories mounted.
  8. Add automated checks that fail closed when the trusted assembler is missing or its integrity cannot be established.

T08 · Insecure Dependencies

Note
Location
README.md:27
Finding

Unpinned Third-Party Dependency Installation Produces Non-Reproducible Builds

Content
View full analysis

Vulnerability Details

File Location: README.md:27-31
Vulnerability Type: Unconstrained package installation without integrity verification
Risk Level: Low

Complete Code Snippet

bash
pip install python-pptx

Technical Analysis

The setup instructions install python-pptx without a version constraint, lockfile, package hash, or explicitly trusted package index. The installed code therefore depends on whichever version the configured package index resolves at installation time.

Package installation may execute build-backend or setup-related code. If the configured index, dependency resolution chain, local pip configuration, or selected package release is compromised, installation can introduce attacker-controlled code into the environment.

No evidence shows that python-pptx itself is malicious. The finding concerns the unsafe and non-reproducible dependency acquisition process, not the legitimacy of the named package.

Attack Path

  1. A user follows the setup command in README.md.
  2. pip queries the user's configured package index and resolves the current available release and transitive dependencies.
  3. No lockfile or hash validates the exact artifacts selected.
  4. A compromised index, compromised release, malicious mirror, or unsafe pip configuration supplies an altered artifact.
  5. Installation or later package import executes the supplied code with the privileges of the user running pip or the Skill.

Impact Assessment

Exploitation could result in arbitrary code execution with the privileges used for package installation or subsequent Skill execution. Potential access includes the Python environment, project files, generated presentation data, and other files available to that account.

Practical risk is reduced because the documentation names a well-known package rather than an apparent typosquat, and the audited files contain no evidence of an actively malicious depe ...[truncated 131 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin python-pptx and all transitive dependencies to reviewed versions.
  2. Maintain a lockfile generated through a dependency-management tool.
  3. Require package hashes during installation, such as with a hash-locked requirements file.
  4. Use a trusted package index or an internally controlled package mirror.
  5. Install dependencies inside an isolated virtual environment with no unnecessary privileges.
  6. Add automated vulnerability and provenance scanning for resolved dependency artifacts.
  7. Define a controlled update process that reviews and tests dependency changes before modifying pinned versions.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language descriptions and output strings entirely in Chinese, including the module docstring and readiness/success messages. Under the policy, forcing a specific language without opt-in is a locale/language policy violation unless the constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.