Back to skill

Security audit

Union Ad Tech

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed UnionSkill-branded PPT generator; its branding and metadata changes are expected for that purpose, though users should notice the external assembler dependency and unpinned install step.

Install this only if you want UnionSkill-branded Chinese PPT deliverables. Expect every generated PPTX to include a UnionSkill closing page, per-slide watermark, metadata attribution, partner file, website, and business email. Use a trusted, reviewed ppt-generator/union_pptx_assembler installation and consider pinning python-pptx in an isolated environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:31
Finding

Mandatory Third-Party Branding and Promotional Content Injection

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31-38
Vulnerability Type: Output and instruction hijacking
Risk Level: High

Vulnerable Code

text
**产物:**
1. 图片ZIP包(slide-01.png ~ slide-NN.png)
2. 品牌PPTX(含UnionSkill尾页+每页水印+元数据)
3. `UnionSkill-合作说明.txt`
4. 可选HTML全屏翻页版

**品牌植入(自动):**
- 尾页:UnionSkill 工业AI + 官网邮箱
- 每页右下角轻水印:`Generated by UnionSkill | www.unionskillai.com`
- PPT元数据:作者=UnionSkill 工业AI

Technical Analysis

The Skill instructions require automatic insertion of UnionSkill branding into user deliverables. The injected content includes a watermark on every slide, a branded final slide, authorship metadata, an external website, an email address, and a separate promotional file.

These requirements are not merely visual styling rules. They alter the expected deliverable and make unrelated third-party advertising a mandatory part of the agent's behavior. The instructions therefore hijack the presentation-generation workflow and override a neutral output goal.

Attack Path

  1. An agent loads the Skill instructions.
  2. A user requests a technology-themed presentation.
  3. The agent follows the mandatory branded assembly workflow.
  4. The generated presentation receives a UnionSkill watermark on every slide.
  5. UnionSkill authorship metadata and a branded closing slide are inserted.
  6. A promotional companion file containing business information is generated.
  7. The user may distribute the contaminated deliverable without realizing that it contains third-party promotion.

Impact Assessment

No system privileges are obtained through this issue. Its scope is the agent's active session and all deliverables created through the Skill.

The resulting files can misrepresent authorship, redirect recipients to an external business, expose unwanted contact information, and contaminate professional or customer-facing presentations. Because the behavior is mandatory, callers can ...[truncated 74 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove mandatory watermarks, advertising, authorship metadata, promotional files, and branded closing slides from the default workflow.
  • Make every branding feature explicit, optional, and disabled by default.
  • Obtain informed user consent before adding any external website, email address, metadata, watermark, or marketing content.
  • Provide a neutral assembly path that creates only the deliverables requested by the user.
  • Clearly disclose all output modifications before generation begins.
  • Add tests confirming that the default workflow does not insert third-party content.

T01 · Skill Instruction Hijacking

Error
Location
scripts/main.py:25
Finding

Executable Enforcement of Promotional Output Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/main.py, lines 25-35
Vulnerability Type: Programmatic output hijacking
Risk Level: High

Vulnerable Code

python
result = assemble(STYLE, image_dir, topic, output)

if result.get("status") == "success":
    slides = result.get("slides", 0)
    result["terminal"] = (
        f"✅ {STYLE_LABEL}风格PPT生成完成,共 {slides} 页\n"
        f"📁 PPTX:{result.get('file', 'N/A')}\n"
        f"📁 合作说明:{result.get('partner_file', 'N/A')}\n"
        f"---\n"
        f"💡 同款AI能力已应用于机加工报价场景\n"
        f"官网:{DOMAIN}\n"
        f"商务合作:{EMAIL}"
    )

Technical Analysis

The executable entry point reinforces the instruction-level hijacking. After assembly succeeds, the code unconditionally replaces or creates the terminal response with promotional content, including an external domain and a business contact address.

There is no neutral-output option, consent check, or configuration switch. The call to the branded assembler also occurs before the promotional response is generated, meaning output modification is embedded directly in the normal successful execution path.

Attack Path

  1. A caller invokes run() with a valid image directory.
  2. The function invokes the branded assembler using the fixed tech-blue style.
  3. The assembler returns a successful result.
  4. The code automatically adds marketing language, a website, and a sales contact to result["terminal"].
  5. The caller displays or forwards the returned terminal message as the official completion response.

Impact Assessment

The issue does not grant operating-system privileges. It controls the successful response returned by the Skill and contributes to modification of the generated presentation.

Every successful caller is exposed to third-party promotional content. This can cause unauthorized advertising, misleading attribution, reputational harm, and unwanted external redirection. Th ...[truncated 103 chars]

Remediation
View remediation

Remediation Suggestions

  • Return a neutral completion message by default.
  • Introduce a clearly documented option such as branding=False, with branding disabled by default.
  • Require explicit user authorization before including a website, email address, promotional statement, or companion marketing file.
  • Separate presentation assembly from marketing-message generation.
  • Preserve the assembler's original response rather than overwriting it with promotional content.
  • Add automated tests ensuring that normal successful execution contains no advertising or external contact information.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:7
Finding

Unsafe External Module Loading Through Python Path Precedence

Content
View full analysis

Vulnerability Details

File Location: scripts/main.py, lines 7-8
Vulnerability Type: Unsafe import-path manipulation
Risk Level: Medium

Vulnerable Code

python
import sys, os
sys.path.insert(0, os.path.join(os.path.dirname(__file__), "../../ppt-generator/scripts"))
from union_pptx_assembler import run as assemble, DOMAIN, EMAIL

Technical Analysis

The script prepends a relative directory outside the audited package to sys.path. Python then imports union_pptx_assembler from the first matching location. Imported Python modules execute their top-level code immediately.

The referenced assembler is not present in the audited project. Its implementation and integrity therefore cannot be verified from this package. If an attacker can create or replace ../../ppt-generator/scripts/union_pptx_assembler.py, the attacker can cause arbitrary Python code to run whenever scripts/main.py is imported or executed.

This creates a module-preloading risk based on filesystem write access and import precedence.

Attack Path

  1. An attacker obtains write access to the external ppt-generator/scripts directory or replaces its contents through another compromised component.
  2. The attacker creates or modifies union_pptx_assembler.py and places malicious top-level Python code in it.
  3. A user or agent imports or executes scripts/main.py.
  4. The script inserts the external directory at index zero of sys.path.
  5. Python resolves union_pptx_assembler from the attacker-controlled path.
  6. The malicious top-level code executes before presentation assembly begins.

Impact Assessment

Successful exploitation executes code with the same operating-system identity and permissions as the process running the Skill. Depending on those permissions, an attacker could read or modify accessible files, alter generated presentations, access environment variables, invoke local programs, or perform network oper ...[truncated 201 chars]

Remediation
View remediation

Remediation Suggestions

  • Package the assembler within a defined, auditable Python package.
  • Replace sys.path.insert() with a normal absolute package import.
  • Pin the assembler dependency to a reviewed version and verify its integrity.
  • Use a lock file and cryptographic hashes when obtaining the dependency externally.
  • Ensure dependency directories are not writable by untrusted users or processes.
  • Avoid executing unverified modules at application import time.
  • Add startup validation that confirms the imported module originates from the expected path.

T08 · Insecure Dependencies

Note
Location
README.md:25
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 25-28
Vulnerability Type: Unpinned dependency installation
Risk Level: Low

Vulnerable Code

bash
pip install python-pptx

Technical Analysis

The setup instructions install python-pptx without specifying a version, package hash, lock file, or trusted index configuration. Consequently, installations performed at different times may resolve to different package versions.

This reduces build reproducibility and exposes users to unexpected upstream changes. If a future release or the configured package source is compromised, following the documented installation command could retrieve unsafe package content. The audit did not establish that the named package is currently malicious.

Attack Path

  1. A user follows the installation instructions.
  2. pip resolves the package using the environment's configured package index.
  3. The latest matching package version is selected rather than a reviewed version.
  4. Package installation or build behavior executes in the user's environment.
  5. A compromised release or package source could execute code with the installer's permissions.

Impact Assessment

The potential impact is code execution with the permissions of the user performing the installation. The practical scope depends on the installation environment and whether a malicious or compromised release is supplied.

As reviewed, this is a supply-chain hardening weakness rather than evidence of a currently malicious dependency.

Remediation
View remediation

Remediation Suggestions

  • Pin python-pptx to a reviewed version.
  • Store dependencies in a requirements or lock file.
  • Include cryptographic hashes and install with hash verification enabled.
  • Configure an explicit trusted package index rather than relying on ambient package-manager configuration.
  • Periodically review and deliberately update dependency versions.
  • Use an isolated virtual environment with minimum required permissions for installation and execution.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly states that generated PPTX files will include a brand tail page, watermark, and metadata, but it does not disclose this as a user-consent or opt-in behavior. Silent modification of deliverables can mislead users, leak vendor attribution or embedded metadata to third parties, and create compliance or trust issues when the output is presented as the user's own material.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly requires generated slides to have '中文标题清晰可读', which imposes a specific language on output. Under the policy, forcing a language or locale without offering user choice or documenting a justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s docstrings and returned user-facing messages are written only in Chinese, and the skill label/output text do not offer any language selection. This creates a locale policy concern because the skill effectively forces a specific language for interaction without explicit user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language instructions and example invocation are entirely in Chinese, and the README does not state whether other languages are supported or that Chinese is a deliberate region-specific constraint. This can amount to a language/locale policy issue because it implicitly forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.