Back to skill

Security audit

ai-ppt-powerpoint-generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is an external image/PPT generation integration, but it exposes broader and potentially sensitive editing capabilities than its PowerPoint-focused name suggests.

Review this carefully before installing. Use it only with non-sensitive prompts and images unless you are comfortable sending them to the DeepNLP/Craftsman services, and avoid using the broader photo-editing or watermark-removal template unless that capability is explicitly intended and permitted for your use case.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is branded and described as a PowerPoint/image-carousel generator, but its documented supported templates include broader capabilities such as icon design, app-store assets, logo design, and photo editing. This scope mismatch can cause users or upstream agents to invoke functionality beyond expected boundaries, weakening least-privilege and increasing the chance of unsafe or policy-violating use.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The documented `photo-editor` template includes watermark removal, which is unrelated to a PPT generator and enables potentially abusive image manipulation. In this skill context, that feature materially increases misuse risk because a caller expecting presentation generation could silently gain access to copyright-evasive editing functionality.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation instructs users to send prompts and uploaded images to external services and returns `share_url` links exposing generated workspaces, but it does not clearly warn about this data flow or sharing exposure. Users may unknowingly disclose sensitive prompts, proprietary images, or generated content to third-party infrastructure or to anyone with the shareable URL.

Static analysis

No suspicious patterns detected.