Back to skill

Security audit

一站式学术Journal Club PPT制作技能,从PDF直达组会演示PPT!

Security checks for vulnerabilities and agentic risk

Overview

This skill gives guidance for creating and checking academic slide decks from research PDFs, with no hidden or disproportionate behavior found.

Install appears reasonable for a slide-generation skill. If dependencies are needed, use a local virtual environment and prefer pinned, reviewed package versions from a trusted package index, especially when processing private papers or unpublished research.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/python-pptx-render-qa-first-pass.md:8
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: references/python-pptx-render-qa-first-pass.md, line 8
Vulnerability Type: Supply-chain exposure through unpinned third-party packages
Risk Level: Medium

Complete Snippet:

markdown
- `python3 -m venv` + local installs (`pymupdf`, `python-pptx`, `pillow`, `markitdown`) solved missing-PyMuPDF problems without relying on system Python.

Technical Analysis

The workflow recommends installing four third-party Python packages but does not specify exact versions, package hashes, a lockfile, or an explicitly trusted package index. A virtual environment provides dependency isolation but does not verify package provenance or integrity.

If an agent interprets this note as an instruction to install the latest available packages, dependency contents may change between runs. A compromised package release, malicious package-index configuration, dependency-confusion condition, or transitive dependency compromise could introduce attacker-controlled code. Python packages can execute code during build or installation, and imported packages execute code with the privileges of the invoking process.

No malicious package, repository, or installation command is embedded in the audited project. This finding concerns the unsafe reproducibility and supply-chain characteristics of the documented installation practice.

Attack Path

  1. An agent encounters a system where one or more listed packages are unavailable.
  2. Following the reference, it creates a virtual environment and installs the packages by name without version or hash verification.
  3. The package resolver contacts the configured package index and selects the currently available releases and transitive dependencies.
  4. An attacker compromises a selected release, dependency, or package source, or exploits an unsafe index configuration.
  5. Attacker-controlled build, installation, or import-time code executes under the account running the slide-generation ...[truncated 798 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add a reviewed dependency manifest or lockfile containing exact package and transitive-dependency versions.
  2. Record cryptographic hashes and install with hash enforcement, such as pip install --require-hashes -r requirements.txt.
  3. Configure and document an approved HTTPS package index rather than relying on an arbitrary environment-level index configuration.
  4. Disable unnecessary fallback indexes and review protections against dependency confusion.
  5. Prefer prebuilt, verified wheels where practical, and avoid executing unreviewed source builds.
  6. Scan and periodically update the locked dependency set through a controlled review process.
  7. Run document processing in a least-privileged, isolated environment without credentials or unrelated sensitive files.
  8. Revise the reference so it points to the pinned manifest instead of recommending package-name-only installation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.