Back to skill

Security audit

Sum2Slides Pro

Security checks for vulnerabilities and agentic risk

Overview

Sum2Slides is a local text-to-PowerPoint tool whose file access and optional setup behavior match its stated purpose.

Install in a virtual environment, review output paths before conversion because files may be overwritten, and use pinned or locked dependencies for production. Non-Chinese users should explicitly set language options where available.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/setup.py:50
Finding

Mutable and unverified dependencies are installed from the configured Python package index

Content
View full analysis
=0.6.21 markdown>=3.4.4 pydantic>=2.0.0 click>=8.1.0 pyyaml>=6.0 ``` `requirements-dev.txt:1-6`: ```text pytest>=7.0.0 pytest-cov>=4.0.0 flake8>=6.0.0 black>=23.0.0 mypy>=1.0.0 pre-commit>=3.0.0 ``` `SKILL.md:19-24, 208-216` documents installation using mutable package and repository references: ```bash pip install sum2slides git clone https://github.com/openclaw/sum2slides.git cd sum2slides pip install -e . pip install -e ".[dev]" ``` ### Technical Analysis ...[truncated 2699 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (60)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The configuration example sets language: "zh" as the default, and the README is entirely written in Chinese without noting that language selection is optional. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy concern unless it is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation is effectively inaccessible to users who cannot read Chinese, yet it does not declare a locale restriction or offer an alternate language. This increases the chance that users misunderstand installation, file-writing behavior, configuration, or operational limitations, which can cause misuse and unsafe execution in agent-driven environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The config sets language: "zh" as the default, which imposes a specific language/locale choice in natural-language behavior. Under the policy, locale restrictions should either offer user choice or be clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code presents its demo title, status messages, inline documentation, and usage examples only in Chinese, which effectively forces a specific language for users. The file does not provide any opt-in, alternative locale, or justification that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/setup.py (reported line 43)May include surrounding context.

python
for package in required_packages:
        try:
            __import__(package.replace('-', '_'))
            print(f"✓ {package} 已安装")
        except ImportError:
            missing_packages.append(package)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup.py (reported line 63)May include surrounding context.

python
try:
        # 使用pip安装
        subprocess.check_call([sys.executable, '-m', 'pip', 'install'] + missing_packages)
        print("✓ 依赖安装成功")
        return True
    except subprocess.CalledProcessError as e:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup.py (reported line 85)May include surrounding context.

python
print("\n设置开发环境...")
    
    try:
        subprocess.check_call([sys.executable, '-m', 'pip', 'install'] + dev_packages)
        print("✓ 开发依赖安装成功")
        return True
    except subprocess.CalledProcessError as e:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup.py (reported line 122)May include surrounding context.

python
try:
        # 使用pip安装当前目录的包
        subprocess.check_call([sys.executable, '-m', 'pip', 'install', '-e', '.'])
        print("✓ Sum2Slides安装成功")
        return True
    except subprocess.CalledProcessError as e:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup.py (reported line 136)May include surrounding context.

python
print("\n运行测试...")
    
    try:
        subprocess.check_call([sys.executable, '-m', 'pytest', 'tests/', '-v'])
        print("✓ 所有测试通过")
        return True
    except subprocess.CalledProcessError:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The configuration documentation and default config set language to "zh", which imposes a specific language/locale by default. This is a natural-language policy concern because the file does not present a user choice or justify a mandatory Chinese locale as region-specific behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The --language option defaults to zh, and the CLI help/messages are written in Chinese, which imposes a specific language/locale by default rather than offering neutral behavior or explicit opt-in. The policy allows locale constraints only when users are given a choice or the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · src/sum2slides/cli.py (reported line 275)May include surrounding context.

python
all_ok = True
    for module_name, display_name in required_modules:
        try:
            __import__(module_name)
            click.echo(f"✓ {display_name} 已安装")
        except ImportError:
            click.echo(f"✗ {display_name} 未安装")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language strings and defaults are exclusively in Chinese, including user-facing fallback titles such as "演示文稿", "总结", and "感谢观看". This indicates a fixed language/locale behavior without any visible mechanism for user choice or documented region-specific justification, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s natural-language behavior and defaults are Chinese-specific, including Chinese descriptions and the hard-coded fallback title "演示文稿" at L092. Under the policy, forcing a specific language or locale without offering user choice or documenting a justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This Python file contains user-facing natural-language text entirely in Chinese, including module/class docstrings and generated slide notes such as "欢迎开始演示" and "演示结束,感谢观看". Under the policy, forcing a specific language without user opt-in or a documented region-specific justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs a filesystem write operation by creating the output directory with os.makedirs(). While the function has comments/docstrings for validation logic, there is no explicit user-facing disclosure, confirmation, or visible notice that validation may modify the filesystem by creating directories.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's human-facing natural-language content is consistently in Chinese, including module and class docstrings and later generated metadata such as subject/keywords. Under the stated policy, forcing a specific language without user opt-in is a locale-policy concern unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The exporter writes Chinese strings into PPTX core properties for subject and keywords regardless of user preference. This is a user-visible locale decision embedded in output content, and no language selection or regional justification is provided in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The language field is hard-coded with a default value of "zh", which imposes a specific locale/language behavior in the model. Under the policy, forcing a specific language without user opt-in or clear region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains user/developer-facing natural-language content exclusively in Chinese, including docstrings, field descriptions, and validation error text. Under the stated policy, forcing a specific language without user opt-in or documented justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module-level docstring, function docstrings, and user-visible exception messages are all written in Chinese, which imposes a single language on users and developers interacting with the skill. The file does not indicate that the skill is intentionally region-specific or provide any opt-in or alternative locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

At L027, the test asserts that document.language == "zh", which semantically requires the parser behavior to default to or force Chinese. This is a natural-language locale constraint and there is no indication in this file that users can choose another language or that the restriction is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains docstrings and all user-visible console messages in Chinese, including status output and next-step instructions. Because the skill does not offer language selection or document that it is intentionally limited to Chinese users, it conflicts with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely written in Chinese, including usage guidance and status information, and does not indicate that users may select another language. Under the policy rule for language or locale constraints, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is entirely written in Chinese, including headings, checklist items, and conclusions, with no indication that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.