Back to skill

Security audit

Interior Proposal Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local interior-design proposal deck generator, and its file access and dependencies fit that purpose.

Install this when you want an interior-design proposal PPT generator. Be aware that its trigger wording is somewhat broad, so confirm the task is for a residential or commercial interior-design deck, and only point the image option at folders whose images you are comfortable including in the generated presentation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad presentation-related terms like 'PPT生成' and '方案汇报', which can match many ordinary user requests outside this skill's intended interior-design scope. Over-broad activation can cause the wrong skill to run, leading to unintended file handling, irrelevant outputs, or bypass of more appropriate task-specific safeguards.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation conditions describe common business scenarios like making proposal decks or preparing bid documents without strict constraints tying them to interior-design projects. Ambiguous routing increases the chance of accidental invocation in unrelated workflows, which can expose project assets to the wrong automation path or generate misleading deliverables.

Static analysis

No suspicious patterns detected.