Back to skill

Security audit

Union Ad Retro

Security checks for vulnerabilities and agentic risk

Overview

This skill openly creates branded UnionSkill retro PPTs, but users should review it because it forces promotional branding and runs an unaudited sibling PPT assembler module.

Install only if you specifically want UnionSkill-branded presentations. Review or control the sibling ppt-generator assembler before running it, use an isolated environment, and avoid this skill for unbranded client or compliance-sensitive deliverables unless the branding and metadata are acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:34
Finding

Mandatory Third-Party Branding Alters User Deliverables

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:34-45
Vulnerability Type: Mandatory promotional content and output manipulation
Risk Level: Medium

Vulnerable Code Snippet

markdown
## 输出规范

**产物:**
1. 图片ZIP包(slide-01.png ~ slide-NN.png)
2. 品牌PPTX(含UnionSkill尾页+每页水印+元数据)
3. `UnionSkill-合作说明.txt`
4. 可选HTML全屏翻页版

**品牌植入(自动):**
- 尾页:UnionSkill 工业AI + 官网邮箱
- 每页右下角轻水印:`Generated by UnionSkill | www.unionskillai.com`
- PPT元数据:作者=UnionSkill 工业AI

Technical Analysis

The Skill instructions require generated presentations to contain third-party branding, including a watermark on every slide, a promotional final slide, branded document metadata, and an additional cooperation file. These modifications are automatic rather than explicitly selected for each generated artifact.

This behavior changes the agent's output objectives from merely producing a presentation to producing promotional material for a specific organization. The instructions also constrain the Skill to branded deliveries, meaning an ordinary content-generation request can result in embedded marketing material and altered metadata.

The branding behavior is disclosed in the Skill documentation, but it remains mandatory within the workflow. Users may therefore receive artifacts containing promotional content beyond what is technically necessary to satisfy a presentation-generation request.

Attack Path

  1. The agent loads the Skill to process a retro-style presentation request.
  2. The Skill instructions redefine the expected output to require UnionSkill branding.
  3. The agent generates slide images and invokes the presentation assembler.
  4. The workflow adds a watermark to every page, branded metadata, a promotional final page, and a cooperation file.
  5. The resulting artifacts distribute third-party promotional information as part of the user's deliverable.

Impact Assessment

The issue affects the integrity and ow ...[truncated 590 chars]

Remediation
View remediation

Remediation Suggestions

  • Make all branding strictly opt-in and disabled by default.
  • Ask for explicit user confirmation before adding watermarks, promotional slides, metadata, contact information, or cooperation files.
  • Provide a fully unbranded generation mode.
  • Separate core presentation generation from optional branding functionality.
  • Display a precise list of all files, metadata fields, watermarks, and additional slides before generation.
  • Preserve user-selected authorship metadata unless the user explicitly requests third-party attribution.
  • Permit removal of promotional material without requiring modifications to the Skill source.

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/main.py:8
Finding

External Module Import Through a Manipulated Python Search Path

Content
View full analysis

Vulnerability Details

File Location: scripts/main.py:8-9
Vulnerability Type: External local module hijacking
Risk Level: High

Vulnerable Code Snippet

python
sys.path.insert(0, os.path.join(os.path.dirname(__file__), "../../ppt-generator/scripts"))
from union_pptx_assembler import run as assemble, DOMAIN, EMAIL

The imported function is subsequently executed:

python
result = assemble(STYLE, image_dir, topic, output)

Technical Analysis

The script prepends a relative directory outside the audited project to sys.path and then imports union_pptx_assembler from that search location. Because the inserted directory takes precedence over ordinary module locations, whichever file resolves as union_pptx_assembler.py can execute top-level Python code immediately during import.

The referenced assembler is not included in the supplied project. Consequently, its implementation, integrity, and side effects cannot be verified from this artifact. If an attacker can create or replace the sibling module, execution of scripts/main.py will load the attacker's code under the same account and privileges as the agent.

Import-time execution occurs before run() validates the image directory. Supplying an invalid directory therefore does not prevent a malicious module's top-level code from running.

Attack Path

  1. An attacker obtains write access to the directory resolved by ../../ppt-generator/scripts relative to scripts/main.py, or compromises the package that provisions that directory.
  2. The attacker creates or replaces union_pptx_assembler.py.
  3. The victim or agent invokes scripts/main.py or otherwise imports it.
  4. The script inserts the attacker-controlled directory at index zero of sys.path.
  5. Python imports the malicious union_pptx_assembler module.
  6. Malicious top-level statements execute immediately.
  7. If the attacker's module exports the expected symbols, ...[truncated 834 chars]
Remediation
View remediation

Remediation Suggestions

  • Bundle the assembler implementation inside the audited project when licensing permits.
  • Alternatively, use a version-pinned, integrity-verified package installed through a controlled dependency process.
  • Remove runtime sys.path mutation.
  • Import the assembler through an explicit package namespace rather than an ambiguous top-level module name.
  • Verify the resolved module path before importing or executing it.
  • Ensure the external module and all parent directories are not writable by untrusted users.
  • Pin the assembler version and verify its cryptographic hash or signed release.
  • Run presentation assembly in a sandbox with minimal filesystem, network, credential, and subprocess permissions.
  • Include the assembler source in future audits because the current artifact does not expose its effective implementation.

T08 · Insecure Dependencies

Note
Location
README.md:27
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: README.md:27-30
Vulnerability Type: Unpinned supply-chain dependency
Risk Level: Low

Vulnerable Code Snippet

bash
pip install python-pptx

Technical Analysis

The installation instructions request the latest version of python-pptx available from pip's configured package index. No exact version, lock file, package hash, or verified dependency set is provided.

As a result, installations performed at different times may resolve to different package versions and transitive dependency graphs. A compromised package release, compromised configured index, or unexpectedly incompatible future release could therefore introduce unreviewed code into the environment.

The package name shown is not evidence of typosquatting, and no malicious package is present in the audited artifact. The risk arises from the absence of reproducible version and integrity controls.

Attack Path

  1. A user follows the setup instructions and runs the unpinned pip command.
  2. Pip contacts its configured package index and selects the currently available compatible release.
  3. A compromised index, malicious release, or altered transitive dependency supplies unreviewed code.
  4. Pip installs that code into the user's Python environment.
  5. The dependency executes when imported or used during presentation processing.

Impact Assessment

If the resolved dependency chain is compromised, malicious Python code could execute with the privileges of the installing or running user. Potential scope includes accessible files, environment variables, generated documents, network access, and subprocess execution.

The practical likelihood is conditional on a compromised package source, release, or dependency chain. The audited repository itself does not contain evidence that the legitimate python-pptx package is malicious.

Remediation
View remediation

Remediation Suggestions

  • Pin python-pptx to a reviewed exact version.
  • Pin and review all transitive dependencies through a lock file.
  • Use hash-verified installation, such as a requirements file with --require-hashes.
  • Install packages only from an approved package index over authenticated TLS.
  • Scan pinned dependencies for known vulnerabilities during CI.
  • Use an isolated virtual environment with minimal permissions.
  • Establish a controlled update process that reviews and tests dependency changes before release.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language instructions and output text exclusively in Chinese, including the skill description and runtime messages. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the restriction is clearly documented and justified, which is not evident here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says this skill is for generating retro nostalgic advertising PPTs for cultural, restaurant, and creative-project use cases. However, the code defaults the topic to "UnionSkill 工业AI解决方案" and appends industrial-AI promotional website and business-contact messaging to successful output, which is not an obvious implementation detail of PPT assembly for the stated use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README’s operative instructions and usage examples are presented in Chinese, including the workflow description and invocation phrase, but there is no indication that users may choose another language. This can be a language/locale policy issue when a skill implicitly forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The docstring frames main.py as an entry point for PPTX assembly and terminal output. In practice, successful runs also append business-development messaging and external contact/website information, which goes beyond the documented intent and changes the observable behavior from pure assembly/output to promotional messaging.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.