Back to skill

Security audit

PPT生成器

Security checks for vulnerabilities and agentic risk

Overview

This PowerPoint skill appears purpose-aligned overall, but it should be reviewed because its setup and helper scripts reach beyond a narrow PPTX-only scope.

Install only if you are comfortable with a presentation skill that can run local Office conversion tools and modify presentation files. Prefer using a dedicated virtual environment, project-local npm dependencies with pinned versions, and a restricted workspace without sensitive environment variables or unrelated documents.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:154
Finding

Unpinned Third-Party Dependencies Installed from Package Registries

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:154-157, pptxgenjs.md:9, and pptxgenjs.md:231
Vulnerability Type: Unpinned and globally installed third-party dependencies
Risk Level: Medium

Vulnerable code snippets:

SKILL.md:154-157

bash
pip install "markitdown[pptx]" Pillow defusedxml

# Node.js: create presentations from scratch
npm install -g pptxgenjs

pptxgenjs.md:9

bash
C:\Users\Administrator\.workbuddy\binaries\node\versions\node-v20.18.0-win-x64\npm.cmd install -g pptxgenjs

pptxgenjs.md:231

bash
npm install -g react react-dom sharp react-icons

Technical Analysis

The installation commands do not pin package versions or verify package integrity. Consequently, each installation can resolve to a different package release or transitive dependency than the version originally reviewed.

Python packages are installed without hashes or a locked dependency set. The npm commands also use global installation, which modifies a shared Node.js environment and makes the installed modules available beyond the current project. Some npm packages can execute lifecycle scripts during installation, meaning a compromised package release could run code immediately with the privileges of the user performing the installation.

No malicious package or active compromise was identified in the audited project. The vulnerability is the unsafe dependency acquisition model, which leaves the effective code executed during setup dependent on mutable external registries.

Attack Path

  1. An attacker compromises a named package, one of its transitive dependencies, or the relevant registry account.
  2. The attacker publishes a malicious version containing installation-time or runtime code.
  3. A user or agent follows the documented setup instructions after that version becomes the package manager's default resolution.
  4. Because no exact version, lockfile, or integrity hash is e ...[truncated 1013 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an exact, reviewed version rather than allowing unconstrained resolution.
  2. Maintain lockfiles that record the complete transitive dependency graph and integrity metadata.
  3. For Python, install dependencies in a dedicated virtual environment and require hashes, for example through a fully pinned requirements file used with pip install --require-hashes.
  4. For Node.js, define dependencies in a project-local package.json, commit package-lock.json, and use npm ci instead of global installation.
  5. Avoid npm install -g unless global installation is strictly necessary. If it is required, pin the exact version and execute installation without administrative privileges.
  6. Review package lifecycle scripts, package ownership changes, and transitive dependency updates before approving version changes.
  7. Use trusted registries and consider registry allowlisting, dependency scanning, and software composition analysis in the release workflow.
  8. Run dependency installation and document processing in a restricted environment with minimal filesystem, network, and credential access.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill presents itself as a PPTX-focused helper, yet it explicitly recommends invoking LibreOffice/soffice and other external tools via shell with user-supplied arguments and PATH or environment-based executable resolution. That gap matters because a benign-looking presentation request could cause generic host command execution or processing of non-PPTX files through powerful external programs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill presents itself as a PPTX-focused helper, yet it explicitly recommends invoking LibreOffice/soffice and other external tools via shell with user-supplied arguments and PATH or environment-based executable resolution. That gap matters because a benign-looking presentation request could cause generic host command execution or processing of non-PPTX files through powerful external programs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill presents itself as a PPTX-focused helper, yet it explicitly recommends invoking LibreOffice/soffice and other external tools via shell with user-supplied arguments and PATH or environment-based executable resolution. That gap matters because a benign-looking presentation request could cause generic host command execution or processing of non-PPTX files through powerful external programs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill presents itself as a PPTX-focused helper, yet it explicitly recommends invoking LibreOffice/soffice and other external tools via shell with user-supplied arguments and PATH or environment-based executable resolution. That gap matters because a benign-looking presentation request could cause generic host command execution or processing of non-PPTX files through powerful external programs.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The activation rules trigger on very common words like 'deck,' 'slides,' and 'presentation,' and instruct use any time a PPTX is involved in any way. Overbroad triggering can cause this skill to hijack unrelated tasks and unnecessarily grant shell/file-processing behavior in benign conversations, which is especially risky given the external command usage documented elsewhere in the skill.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/office/soffice.py (reported line 63)May include surrounding context.

python
from office.soffice import get_soffice_env
except ImportError:
    def get_soffice_env():
        return os.environ.copy()

from PIL import Image, ImageDraw, ImageFont

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/thumbnail.py (reported line 29)May include surrounding context.

python
from office.soffice import get_soffice_env
except ImportError:
    def get_soffice_env():
        return os.environ.copy()

from PIL import Image, ImageDraw, ImageFont

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs use of shell commands, file reads/writes, environment-dependent executable lookup, and external tools, but declares no explicit tool scope or permission boundaries. That makes the operational capability opaque to the orchestrator and increases the chance the skill will be invoked with broader host access than intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation advertises and supports packing DOCX and XLSX files even though the skill metadata declares a PPTX-only capability. In an agent setting, this scope mismatch can bypass routing or policy controls that rely on skill declarations, causing the skill to process non-presentation Office documents unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code explicitly allows output suffixes of .docx, .pptx, and .xlsx despite the skill being presented as a PPTX/presentation handler. This increases the chance that an attacker or confused caller can use the skill as a general Office packer, expanding access beyond its declared trust boundary and undermining format-specific governance.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/office/soffice.py (reported line 34)May include surrounding context.

python
# 2. Try "soffice" / "soffice.exe" from PATH
    for name in ("soffice.exe", "soffice", "libreoffice.exe", "libreoffice"):
        try:
            subprocess.run(
                [name, "--version"],
                capture_output=True, timeout=10
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/office/soffice.py (reported line 77)May include surrounding context.

python
"""
    cmd = [_SOFFICE_CMD] + list(args)
    env = get_soffice_env()
    return subprocess.run(cmd, env=env, **kwargs)


if __name__ == "__main__":

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/thumbnail.py (reported line 169)May include surrounding context.

python
# Try using soffice (LibreOffice) to convert to PDF
    try:
        result = subprocess.run(
            [
                "soffice",
                "--headless",

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/thumbnail.py (reported line 193)May include surrounding context.

python
# Convert PDF to JPEG images using pdftoppm (Poppler)
    try:
        result = subprocess.run(
            [
                "pdftoppm",
                "-jpeg",

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file includes an example that writes a presentation to disk via pres.writeFile({ fileName: "output.pptx" }), but the surrounding documentation does not explicitly warn users that running the example will create a local file and may overwrite an existing file with the same name. For markdown files, user-affecting data or system changes should be disclosed when described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This script writes new slide XML and relationship files directly into the target unpacked PPTX directory, and later also updates existing package metadata files. Although there are status prints after the changes, the file does not include a user-facing warning, confirmation, or docstring notice that it will modify presentation contents on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script creates parent directories and saves JPEG grid files based on the provided output prefix, which can modify the filesystem. While this behavior is part of the tool's purpose, there is no explicit confirmation or warning that files will be created or potentially overwritten at the target path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.