Back to skill

Security audit

image-deck: PPT Presentation & Slides

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed image-based slide-deck workflow with normal local output files, though users should understand it produces non-editable image slides and its PPTX numbering helper has a validation weakness for untrusted inputs.

Install this only if you want raster image slides rather than fully editable PowerPoint content. Do not use it for exact charts, dense tables, or text that must remain editable. Treat generated prompt, research, and log files as local work artifacts that may contain source material. If using the PPTX slide-number helper, process trusted presentations and simple font names until its XML input validation is tightened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/add_native_slide_numbers.py:104
Finding

Unescaped Input Interpolation in Generated OOXML

Content
View full analysis
' f'' f'' f'' f'{slide_number}' ) paragraph._p.append(parse_xml(field_xml)) ``` A second XML fragment interpolates `placeholder_idx` without escaping: ```python nv_pr.append(parse_xml( f'' )) ``` The value is obtained from an input presentation: ```python def slide_number_placeholder_idx(slide) -> str: layout_fields = slide.slide_layout._element.xpath( './/p:ph[@type="sldNum"]' ) master_fields = slide.slide_layout.slide_master._element.xpath( './/p:ph[@type="sldNum"]' ) if len(layout_fields) != 1 or len(master_fields) != 1: raise RuntimeError( "PowerPoint-compatible native numbering requires exactly one " "sldNum placeholder in both the slide layout and slide master" ) return layout_fields[0].get("idx", "0") ``` ### Technical Analysis The script constructs OOXML fragments with Python formatted strings and then passes the resulting strings to `parse_xml()`. Two interpolated values are not escaped or constrained: 1. `font_name` is supplied directly through the command-line `--font` argument. 2. `placeholder_idx` originates from the `idx` attribute of a slide-number placeholder in the input PPTX. An XML attribute can contain encoded quote or markup characters that are decoded when ...[truncated 2291 chars]
Remediation
View remediation
str: if not re.fullmatch(r"[0-9]+", value): raise ValueError("slide-number placeholder idx must contain digits only") return value ``` Apply this validation before creating the new placeholder. 3. **Constrain command-line font names.** Enforce a reasonable maximum length and reject control characters and XML-significant characters. Prefer an allowlist of supported fonts when feasible. 4. **Use element construction for the field.** Create `a:fld`, `a:rPr`, `a:latin`, `a:solidFill`, `a:srgbClr`, and `a:t` as separate elements. Set `typeface`, `val`, `id`, and `type` using element attribute APIs rather than string interpolation. 5. **Fail safely on untrusted presentations.** Catch XML and package-processing errors, avoid writing a partial output file, and return a clear validation error. 6. **Add security regression tests.** Test font names and placeholder indices containing quotes, angle brackets, ampersands, encoded entities, excessive lengths, and malformed Unicode. Verify that such input is either safely encoded or rejected and cannot alter the intended OOXML tree. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a content-generation skill for making slide decks via image generation, with explicit conversational triggers and approval-stage behavior. The actual code chunk does something much narrower and materially different: it edits an existing PowerPoint file to add native slide-number placeholders/text fields. While slide numbering could be a supporting utility within a deck-generation system, this code alone does not exhibit the declared primary purpose or workflow. Its main behavior is undeclared post-processing of PPTX files rather than generating presentations, so this is a clear description/behavior mismatch.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to show full prompt groups directly in chat before generation. Exposing detailed internal prompts and visual-bible instructions can leak proprietary system workflow, make downstream prompt manipulation easier, and provide attackers with reusable prompt templates for steering or bypassing intended controls.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
1. **Ask required setup questions** before planning: page count, language, style, text richness/content density, and topic if no source is present.
2. **Read source material or research the topic** before writing the deck plan.
3. **Show a PPT slide-by-slide design document directly in the chat** as the planning preview.
4. **Self-check the complete prompt package internally before showing it**, then show prompt groups directly in the chat, up to 8 slides per group.
5. **Ask for overall design approval only after both the design document and prompt groups are shown.** This confirmation covers the full-deck structure, slide-by-slide content, visual bible, and prompts. Do not ask the user to confirm the design document separately and then confirm prompts again.
6. **After overall design approval, generate exactly one master sample and no other slide.** Approval at this stage authorizes only the sample, even if the user says "confirm generation," "proceed," or similar.
7. **Show the generated master sample in the chat and stop.** Ask the user to approve the sample style or request changes. The review covers the actual palette, typography mood, layout grammar, information density, and overall visual feel. Do not generate another slide, assemble a PPTX/PDF, or start background generation while waiting.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
92% confidence
Finding

This line reinforces a requirement to reveal prompts inline, confirming that prompt disclosure is not incidental but built into the workflow. Repeated mandated prompt exposure increases the chance that sensitive prompt structure, hidden constraints, and tool-routing logic are disclosed to end users and can be copied or adversarially adapted.

Content

Scanner excerpt · SKILL.md (reported line 552)May include surrounding context.

md
- Prefer 12-18 slides for a first pass; 15 is a good default.
- Show the PPT slide-by-slide design document inline before prompt groups. This is required even when source notes or prompt files are also saved, but it is not a separate confirmation gate.
- Default slide design is 图文并茂: each slide should feel like a real PPT page, with text and visuals balanced according to its role and selected content-density mode.
- Show prompts inline in groups of up to 8 slides before generation. This is required even when prompt files are also saved.
- Use two distinct approvals: first approve the overall design to authorize one sample; then approve the displayed sample's style to authorize all remaining slides.
- After generating the sample, stop the turn. Never generate the remaining slides in the same uninterrupted run.
- Keep user-facing confirmation copy natural and concise. Do not expose internal gate terminology or narrate prohibitions unless the user asks how the workflow works.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/prompt-patterns.md (reported line 55)May include surrounding context.

Prompt Group Template

Show prompt groups directly in the conversation before calling image_gen. Use at most 8 slides per group. Do not hide this behind file attachments.

text
请使用 Codex 内置 image_gen 能力生成这一组 <N> 张独立的 16:9 横版 PPT 完整页面图片。

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
## English

`image-deck` is used to create PPT, PowerPoint-style presentations, slide decks, and carousel decks where every page is a complete generated image. It uses Codex built-in `image_gen` (GPT Image 2) to generate slides one by one, with each slide's title, labels, and short copy generated inside the same image.

This skill requires Codex built-in `image_gen` (GPT Image 2).

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger language is intentionally broad and captures very common requests like 'make a PPT' or 'create slides,' which can cause the agent to invoke this specialized image-only workflow when the user actually wanted an editable presentation. That can lead to unintended tool selection, mismatched outputs, and accidental routing away from safer or more appropriate workflows for precise editable business content.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

Codex:

bash
mkdir -p ~/.codex/skills
cp -R skills/image-deck ~/.codex/skills/image-deck

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

Codex:

bash
mkdir -p ~/.codex/skills
cp -R skills/image-deck ~/.codex/skills/image-deck

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Chinese trigger guidance defaults activation on generic PPT requests without requiring confirmation that the user wants rasterized, non-editable, image-generated slides. In multilingual environments, this increases the chance of accidental invocation and user confusion, especially where '做PPT' often implies a standard editable deck.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

A policy to prefer this skill even when the user does not mention it creates ambiguous invocation boundaries and increases the risk of the agent taking the wrong execution path. While not a classic exploit, this can cause unauthorized or unexpected tool behavior relative to user intent, especially when alternate workflows handle attachments, editable charts, or document conversion more safely.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
2. **Read source material or research the topic** before writing the deck plan.
3. **Show a PPT slide-by-slide design document directly in the chat** as the planning preview.
4. **Self-check the complete prompt package internally before showing it**, then show prompt groups directly in the chat, up to 8 slides per group.
5. **Ask for overall design approval only after both the design document and prompt groups are shown.** This confirmation covers the full-deck structure, slide-by-slide content, visual bible, and prompts. Do not ask the user to confirm the design document separately and then confirm prompts again.
6. **After overall design approval, generate exactly one master sample and no other slide.** Approval at this stage authorizes only the sample, even if the user says "confirm generation," "proceed," or similar.
7. **Show the generated master sample in the chat and stop.** Ask the user to approve the sample style or request changes. The review covers the actual palette, typography mood, layout grammar, information density, and overall visual feel. Do not generate another slide, assemble a PPTX/PDF, or start background generation while waiting.
8. **Only after the user explicitly approves the displayed sample style**, generate the remaining slides through Codex `image_gen` (GPT Image 2). Silence, lack of objection, or approval of the earlier overall design is not sample-style approval.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 341)May include surrounding context.

md
2. **Read source material or research the topic** before writing the deck plan.
3. **Show a PPT slide-by-slide design document directly in the chat** as the planning preview.
4. **Self-check the complete prompt package internally before showing it**, then show prompt groups directly in the chat, up to 8 slides per group.
5. **Ask for overall design approval only after both the design document and prompt groups are shown.** This confirmation covers the full-deck structure, slide-by-slide content, visual bible, and prompts. Do not ask the user to confirm the design document separately and then confirm prompts again.
6. **After overall design approval, generate exactly one master sample and no other slide.** Approval at this stage authorizes only the sample, even if the user says "confirm generation," "proceed," or similar.
7. **Show the generated master sample in the chat and stop.** Ask the user to approve the sample style or request changes. The review covers the actual palette, typography mood, layout grammar, information density, and overall visual feel. Do not generate another slide, assemble a PPTX/PDF, or start background generation while waiting.
8. **Only after the user explicitly approves the displayed sample style**, generate the remaining slides through Codex `image_gen` (GPT Image 2). Silence, lack of objection, or approval of the earlier overall design is not sample-style approval.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template hard-codes Chinese user-facing generation instructions and does not preserve or defer to the user's chosen language, even though the skill metadata says the user should choose language. This can cause the agent to ignore user intent, produce prompts/review text in an unexpected language, and create policy or UX failures when the skill is used in multilingual contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The review and approval gates are fixed in Chinese with required exact reply phrases, which removes language choice and can coerce users into interacting in a language they did not select. In an agent workflow, rigid language-gated confirmations can break approval logic, cause user confusion, and lead to incorrect or bypassed human-in-the-loop authorization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated XML sets lang="en-US" for slide-number text and end-paragraph properties, forcing a specific locale in the output. This is a natural-language/locale policy concern because the script provides no user choice or justification for requiring U.S. English.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.