Back to skill

Security audit

MS Investment Deck

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local PowerPoint generator whose file access and dependency use are mostly disclosed and aligned with creating investment-deck PPTX files.

Install this in a virtual environment, consider pinning python-pptx to a reviewed version, and review generated decks for accurate source labels, branding, disclosures, and financial claims before sharing them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:397
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:397-406
Vulnerability Type: Supply-chain exposure caused by an unpinned dependency
Risk Level: Medium

markdown
| Dependency | Version | Description |
|------|------|------|
| Python | >= 3.9 | Runtime |
| python-pptx | >= 0.6.21 | PPTX file generation |

Install the dependency:

```bash
pip install python-pptx
text

### Technical Analysis

The documented installation command installs `python-pptx` without an exact version, cryptographic hash, lockfile, or explicit trusted package index. The documented `>= 0.6.21` constraint also allows any later release to be selected.

Consequently, the code that users execute may differ from the dependency version originally reviewed. If the package distribution channel, a future release, or the user's package-index configuration is compromised, installation could introduce attacker-controlled package code. Python packages can execute code during installation and subsequently when imported by `scripts/ms_investment_deck.py`.

The project does not itself retrieve or execute a remote payload, and no evidence indicates that the named dependency is currently malicious. The risk arises from the unsafe, non-reproducible dependency installation procedure.

### Attack Path

1. An attacker compromises a future release of the dependency, its distribution account, or a package index configured in the victim's environment.
2. A user follows the documented `pip install python-pptx` instruction.
3. Package resolution selects the attacker-controlled release because no exact version or hash is enforced.
4. Malicious package code executes during installation or when the application imports `pptx`.
5. The payload runs with the privileges of the user or automation account performing the installation or executing the Skill.

### Impact Assessment

Successful exploitation could provide arbitrary code execution under the installin
...[truncated 394 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin python-pptx to a specifically reviewed version rather than using an open-ended minimum version.
  2. Record cryptographic hashes and enforce them with pip install --require-hashes.
  3. Maintain a committed lockfile or hashed requirements file for reproducible installations.
  4. Configure installation to use an explicitly trusted package index and disable unintended supplemental indexes where practical.
  5. Run dependency vulnerability and provenance checks in CI, and review updates before changing the pinned version.
  6. Install and run the Skill in a least-privileged virtual environment or container without unnecessary credentials.

Example hardened requirements entry:

text
python-pptx==<reviewed-version> \
    --hash=sha256:<verified-package-hash>

Example installation command:

bash
python -m pip install --require-hashes -r requirements.txt
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The main entrypoint is documented as make_deck(..., language="zh"), establishing Chinese as the default output language. This is reinforced elsewhere in the implementation, so the skill imposes a locale/language preference unless the caller explicitly overrides it, which is a natural-language policy concern when no opt-in is obtained from the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The _normalize_language helper returns "zh" for any unrecognized language value, which silently coerces output into Chinese rather than preserving user intent or prompting for clarification. This creates a locale policy violation because the skill can force a specific language without explicit user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.