T08 · Insecure Dependencies
- Location
scripts/update_notes.py:21- Finding
Automatic Installation of an Unpinned Runtime Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly a local PPT notes helper, but it needs review because it can automatically install software and modify local course files without clear per-run control.
Install only if you are comfortable with the skill reading course DOCX/PPTX files, creating updated PPT copies in those folders, and potentially installing python-pptx through pip. Prefer installing reviewed, pinned dependencies yourself first, require a preview/confirmation before writes, and avoid enabling weekly automatic execution unless you explicitly configure and trust that schedule.
scripts/update_notes.py:21Automatic Installation of an Unpinned Runtime Dependency
scripts/update_ppt_notes.py:25Automatic Installation of an Unpinned Runtime Dependency in the V2 Script
scripts/update_notes.py:30Unbounded Decompression and XML Parsing of DOCX Content
scripts/update_ppt_notes.py:32Unbounded DOCX Decompression and XML Parsing in the V2 Script
The description claims a narrowly scoped document-processing skill, but the detected behavior includes undeclared environment modification and does not actually implement the advertised core logic. This mismatch is dangerous because users may trust the skill to only update notes while it can instead alter the environment or perform unexpected actions, undermining informed consent and security review.
The top-level docstring states that the tool extracts lecturer activities from lesson plans and writes them into PPT notes. However, the code comments and functions show that extraction is not implemented and the PPT save path does not modify any note content, creating a direct contradiction between stated intent and actual behavior.
The manifest and module docstring promise extracting lecturer activities from a teaching plan and automatically writing them into corresponding PPT slide notes. In reality, the extraction function is a stub that returns an empty dictionary, and the update function merely opens and re-saves the presentation without modifying notes.
The skill declares filesystem scanning and likely shell/package-install behavior, but does not declare any tool scope or permissions boundaries. This creates an authorization gap where a user or runtime may invoke broader file access or command execution than expected, especially because the workflow targets a large fixed directory tree on a local drive.
The trigger phrases are broad enough that ordinary language like '更新PPT备注' could activate a workflow that scans directories and creates modified PPT files. Ambiguous activation increases the chance of unintended execution of file-modifying behavior without a sufficiently explicit user request or confirmation.
The skill writes new PPT files alongside originals but does not clearly warn users that it will create derivative files in course directories and preserve/append note content. In a local-drive educational workflow, that omission raises the risk of accidental data sprawl, confusion over authoritative versions, and unintended modification of sensitive teaching materials.
The script automatically installs a dependency with pip at runtime if import fails, causing network-based code retrieval and execution without prior vetting. In a local automation skill that processes user documents, this expands the trust boundary and can expose users to dependency confusion, malicious package delivery, or unexpected environment modification.
Installing packages automatically without explicit warning or consent is risky because it executes an external package manager and alters the host environment unexpectedly. In this context, the skill's stated purpose does not require silent environment changes, so the behavior is disproportionate and increases supply-chain and operational risk.
This skill automatically installs a Python package at runtime even though its stated purpose is local PPT note updating. That behavior is risky because it performs network-dependent software installation and executes third-party package installation logic without explicit user approval, which is unnecessary for the core task and increases supply-chain and environment-tampering risk.
The script invokes pip at runtime via subprocess, which causes code from the Python package ecosystem to be fetched and installed during normal execution. This expands the trust boundary to network/package infrastructure and can lead to execution of unreviewed package install-time code or unexpected environment modification, especially on shared or managed systems.
except ImportError:
print("正在安装 python-pptx 库...")
import subprocess
subprocess.check_call([sys.executable, "-m", "pip", "install", "python-pptx", "-q"])
print("安装完成!")
The natural-language descriptions and user-facing output are entirely in Chinese, which can amount to a language/locale policy issue when no opt-in or justification is provided. There is no indication that the tool is restricted to a Chinese-speaking or region-specific context.
This Python file contains natural-language descriptions and runtime messages exclusively in Chinese, starting with the module docstring and continuing throughout the script. Under the policy, forcing a specific language without offering a user choice or documenting a justified locale restriction is a natural-language policy violation.
No suspicious patterns detected.