Back to skill

Security audit

Deck Web Converter

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but its custom color option can inject active script into the generated shareable HTML, which is risky for confidential decks.

Review before installing or using in automated/shared workflows. Use only trusted input values for --color, prefer the default color until validation is added, avoid hosting generated decks on an authenticated or sensitive origin, and treat each HTML output as containing the original deck's confidential text and images. Install dependencies in a virtual environment and prefer pinned, reviewed versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/convert_deck.py:585
Finding

Unvalidated accent color permits script injection into generated presentations

Content
View full analysis
` template in `generate_html()` **Vulnerability Type**: HTML/CSS template injection leading to arbitrary JavaScript execution **Risk Level**: Medium ### Vulnerable Code ```python parser.add_argument("--color", "-c", default="#1a73e8", help="Accent color (hex)") ``` ```python html = generate_html(slides, title, args.color) ``` The value is inserted directly into the generated HTML's inline style sheet: ```python .progress-fill {{ height: 100%; background: {accent_color}; width: 0%; transition: width 0.3s ease; }} ``` Other CSS rules also interpolate the same unvalidated value. ### Technical Analysis The `--color` command-line argument is described as a hexadecimal color, but the implementation does not validate that it is a color. `accent_color` is inserted directly into a raw `` element without contextual escaping. An attacker who can influence this parameter can supply markup that terminates the style element and creates a script element, for example: ```text ``` HTML character escaping is not applied to this value, and ordinary HTML escaping alone would not be a sufficient substitute for strict color validation. When the generated presentation is opened, the injected script executes in the presentation's browser context. This is especially relevant if another application or agent exposes the converter through a web interface, job queue, automation pipeline, or other mechanism where the color parameter can be supplied by an untrusted party. The separately flagged Base64 behavior is not itself evidence of exfiltration. The script only Base64-encodes images extracted from the selected deck and embeds them in local `data:` URIs, which is necessary for the declared self-contained HTML functionality. No network tra ...[truncated 1746 chars]
Remediation
View remediation
`, `

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned and unhashed dependencies allow uncontrolled supply-chain updates

Content
View full analysis
=0.6.21 pymupdf>=1.23.0 ``` ### Technical Analysis Both dependencies use open-ended lower-bound constraints. A future `pip install -r requirements.txt` may therefore install any newer release available from the configured package index, including future major versions. The file also contains no integrity hashes. The package names correspond to the expected libraries and no dependency-confusion typo was identified. Consequently, this finding does not establish that a currently referenced package is malicious. The risk is that installations are not reproducible and implicitly trust all future releases and the configured package index. Both libraries process complex, attacker-supplied document formats. Uncontrolled upgrades can also introduce behavioral changes or newly published regressions without review. Conversely, permanent pinning without a maintenance process can retain known vulnerabilities, so pins should be updated through deliberate testing and security review. ### Attack Path 1. An attacker compromises a dependency maintainer account, package-index delivery path, or an allowed future release. 2. A malicious or compromised version is published under the legitimate package name with a version satisfying the open-ended `>=` constraint. 3. A user follows the README instruction: ```bash pip install -r requirements.txt ``` 4. `pip` resolves and installs the affected release because no exact version or hash restricts it. 5. Malicious installation hooks, imported module code, or document-processing code executes with the privileges of the user running the converter. This attack path depends on an external supply-chain compromise; no malicious dependency payload was present in the audited project. ### Impact Assessment A compromised depen ...[truncated 585 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill clearly instructs generating and executing Python that writes an output HTML file, but it declares no explicit tool scope or permissions. In agent environments, missing capability declarations can lead to overly broad implicit access, making file writes happen without clear policy enforcement or user understanding of what the skill may modify.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prescribed HTML template sets <html lang="zh-CN">, which forces a specific language/locale regardless of the user's language or the source deck's language. This is a natural-language policy issue because the skill otherwise supports both Chinese and English content and does not document a justified region-specific constraint or ask the user to opt in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README explicitly encourages sharing a self-contained HTML output, but does not warn that all deck text and embedded content may be packaged into a portable file that is easy to redistribute or host publicly. In the context of pitch decks and business plans, this can lead users to unintentionally expose confidential company, financial, or investor information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill directs the agent to save a generated HTML file beside the source document without a prominent user-facing warning or confirmation that a new file will be created. While it does not overwrite the original by design, silent filesystem modification can still surprise users, leak sensitive deck content into an additional artifact, or place files in synced/shared directories.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency is specified with a lower bound only, which allows any newer release to be installed. This weakens build reproducibility and can unintentionally pull in a compromised or breaking version, increasing supply-chain risk over time.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
python-pptx>=0.6.21
pymupdf>=1.23.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

PyMuPDF is also unpinned, so installs are not reproducible and may resolve to different versions in different environments. In a file-conversion skill that processes user-supplied documents, this increases exposure to dependency-level vulnerabilities because parser libraries are security-sensitive.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
python-pptx>=0.6.21
pymupdf>=1.23.0

Unverifiable Dependency: pymupdf has 2 known advisory(ies) (CVE-2026-3029 (PyMuPDF has a path traversal in _main_.py); CVE-2026-3029 (PyMuPDF has a path traversal in _main_.py)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest does not pin PyMuPDF, and the package has known advisories including a path traversal issue in its CLI entrypoint. Because this skill converts uploaded PDF/PPT content and relies on document-parsing software, unresolved package-version ambiguity is more concerning than in a non-parser context: a vulnerable release could be installed without visibility.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.