Back to skill

Security audit

教案内容写入PPT备注

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a local PPT notes helper, but it needs review because it can automatically install software and modify local course files without clear per-run control.

Install only if you are comfortable with the skill reading course DOCX/PPTX files, creating updated PPT copies in those folders, and potentially installing python-pptx through pip. Prefer installing reviewed, pinned dependencies yourself first, require a preview/confirmation before writes, and avoid enabling weekly automatic execution unless you explicitly configure and trust that schedule.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Error
Location
scripts/update_notes.py:21
Finding

Automatic Installation of an Unpinned Runtime Dependency

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/update_ppt_notes.py:25
Finding

Automatic Installation of an Unpinned Runtime Dependency in the V2 Script

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/update_notes.py:30
Finding

Unbounded Decompression and XML Parsing of DOCX Content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/update_ppt_notes.py:32
Finding

Unbounded DOCX Decompression and XML Parsing in the V2 Script

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims a narrowly scoped document-processing skill, but the detected behavior includes undeclared environment modification and does not actually implement the advertised core logic. This mismatch is dangerous because users may trust the skill to only update notes while it can instead alter the environment or perform unexpected actions, undermining informed consent and security review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-level docstring states that the tool extracts lecturer activities from lesson plans and writes them into PPT notes. However, the code comments and functions show that extraction is not implemented and the PPT save path does not modify any note content, creating a direct contradiction between stated intent and actual behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest and module docstring promise extracting lecturer activities from a teaching plan and automatically writing them into corresponding PPT slide notes. In reality, the extraction function is a stub that returns an empty dictionary, and the update function merely opens and re-saves the presentation without modifying notes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares filesystem scanning and likely shell/package-install behavior, but does not declare any tool scope or permissions boundaries. This creates an authorization gap where a user or runtime may invoke broader file access or command execution than expected, especially because the workflow targets a large fixed directory tree on a local drive.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough that ordinary language like '更新PPT备注' could activate a workflow that scans directories and creates modified PPT files. Ambiguous activation increases the chance of unintended execution of file-modifying behavior without a sufficiently explicit user request or confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill writes new PPT files alongside originals but does not clearly warn users that it will create derivative files in course directories and preserve/append note content. In a local-drive educational workflow, that omission raises the risk of accidental data sprawl, confusion over authoritative versions, and unintended modification of sensitive teaching materials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script automatically installs a dependency with pip at runtime if import fails, causing network-based code retrieval and execution without prior vetting. In a local automation skill that processes user documents, this expands the trust boundary and can expose users to dependency confusion, malicious package delivery, or unexpected environment modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Installing packages automatically without explicit warning or consent is risky because it executes an external package manager and alters the host environment unexpectedly. In this context, the skill's stated purpose does not require silent environment changes, so the behavior is disproportionate and increases supply-chain and operational risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill automatically installs a Python package at runtime even though its stated purpose is local PPT note updating. That behavior is risky because it performs network-dependent software installation and executes third-party package installation logic without explicit user approval, which is unnecessary for the core task and increases supply-chain and environment-tampering risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
94% confidence
Finding

The script invokes pip at runtime via subprocess, which causes code from the Python package ecosystem to be fetched and installed during normal execution. This expands the trust boundary to network/package infrastructure and can lead to execution of unreviewed package install-time code or unexpected environment modification, especially on shared or managed systems.

Content

Scanner excerpt · scripts/update_ppt_notes.py (reported line 25)May include surrounding context.

python
except ImportError:
        print("正在安装 python-pptx 库...")
        import subprocess
        subprocess.check_call([sys.executable, "-m", "pip", "install", "python-pptx", "-q"])
        print("安装完成!")

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language descriptions and user-facing output are entirely in Chinese, which can amount to a language/locale policy issue when no opt-in or justification is provided. There is no indication that the tool is restricted to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains natural-language descriptions and runtime messages exclusively in Chinese, starting with the module docstring and continuing throughout the script. Under the policy, forcing a specific language without offering a user choice or documenting a justified locale restriction is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.