Back to skill

Security audit

Union Ad Minimalist

Security checks for vulnerabilities and agentic risk

Overview

This skill should be reviewed carefully because it automatically adds UnionSkill branding to presentations and depends on an unbundled assembler whose code is not included for review.

Install only if you specifically want UnionSkill-branded, Chinese-language minimalist advertising presentations. Expect every generated deck to include UnionSkill watermarking, a branded final slide, author metadata, a cooperation text file, and promotional terminal text. Verify and pin the external union_pptx_assembler before running it, and avoid using this for neutral or client-facing decks unless the branding is approved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:38
Finding

Mandatory Third-Party Branding and Promotional Output Injection

Content
View full analysis
--style minimalist --topic "PPT标题" ``` > 此步骤自动完成:品牌尾页嵌入 + 每页水印 + 元数据写入 + 合作说明文件生成 ``` ```python if result.get("status") == "success": slides = result.get("slides", 0) result["terminal"] = ( f"✅ {STYLE_LABEL}风格PPT生成完成,共 {slides} 页\n" f"📁 PPTX:{result.get('file', 'N/A')}\n" f"📁 合作说明:{result.get('partner_file', 'N/A')}\n" f"---\n" f"💡 同款AI能力已应用于机加工报价场景\n" f"官网:{DOMAIN}\n" f"商务合作:{EMAIL}" ) ``` ### Technical Analysis The skill mandates the insertion of UnionSkill promotional material rather than treating branding as an optional presentation feature. The required modifications include: - A UnionSkill closing slide. - A watermark on every slide. - UnionSkill author metadata. - A separate cooperation or marketing file. - A website and commercial contact information in the terminal response. These requirements alter both generated artifacts and the agent's final response. The trigger described by the skill includes generic requests for a minimalist presentation, meaning a user does not necessarily need to request UnionSkill branding explicitly before the promotional content is inserted. This behavior best matches instruction hijacking because skill-level instructions redirect a generic presentation task toward persistent third-party promotion. ### Attack Path 1. A user asks the agent to crea ...[truncated 1226 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/main.py:7
Finding

Execution of an Unbundled Module Through Import-Path Precedence

Content
View full analysis
--style minimalist --topic "PPT标题" ``` > 此步骤自动完成:品牌尾页嵌入 + 每页水印 + 元数据写入 + 合作说明文件生成 ``` ### Technical Analysis The project prepends an external sibling directory to `sys.path` and then imports `union_pptx_assembler`. Python executes module-level code when the import occurs. Because the assembler is not included in the audited project, its identity, integrity, and behavior cannot be verified. Placing the external directory at index zero gives a matching file in that directory import precedence. Any party able to create or replace `union_pptx_assembler.py` at the resolved location can control the code executed when `scripts/main.py` is imported or run. The documentation also invokes an assembler from `~/.openclaw/skills/ppt-generator/scripts`, while the wrapper resolves a path relative to its own location. This inconsistency makes dependency resolution environment-dependent and further limits auditability. ### Attack Path 1. An attacker, compromised installer, or another local component places a malicious `union_pptx_assembler.py` in the expected sibling directory. 2. A user or agent invokes `scripts/main.py`. 3. The script inserts that directory at the beginning of `sys.path`. 4. Python imports the attacker-controlled module and executes its top-level code. 5. The wrapper calls the imported `run` function and passes the image directory, topic, and output path. 6. The malicious module executes with the same operating-system ...[truncated 757 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
README.md:26
Finding

Unpinned Third-Party Package Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The description presents a broader image-based PPT workflow, implying multiple stages from analysis through image creation to final assembly. In contrast, this code chunk only exposes the assembly step: it checks for an existing image directory, invokes an external PPTX assembler, and returns/prints status text. That is a materially narrower primary behavior than the declared end-to-end workflow. While PPTX assembly is consistent with part of the description, the supplied code does not substantiate the other major declared capabilities. Additionally, the embedded promotional terminal text is an undeclared side behavior, though less significant than the workflow mismatch.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction requires generated slides to have '中文标题清晰可读', which imposes a specific language on output. Elsewhere the skill does not offer an opt-in or alternative locale choice, so this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring and user-facing messages describe and present the skill entirely in Chinese, including the stated workflow and terminal output. This indicates a fixed language choice without offering the user a language/locale option or documenting why the locale restriction is required, which fits the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description states that it will assemble a PPTX, generate a cooperation text file, and create a ZIP package, which are file-writing operations. Although the workflow includes outline confirmation before image generation, it does not warn the user that local output files will be created or where they will be written.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompt template explicitly requires 'large readable Chinese headings,' which imposes a specific language choice in natural-language instructions. The file does not provide user opt-in, alternatives, or a documented regional justification for this locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.