Back to skill

Security audit

爱图表 AIPPT

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a real PPT-generation integration, but it asks users to paste an API key into chat and ships a broader API CLI than the PPT purpose requires.

Review before installing. Use this only if you trust the publisher with your aitubiao account API key, understand that the key is stored locally for later sessions, and are comfortable that the bundled CLI can perform non-PPT aitubiao actions if invoked. Prefer a restricted or temporary API key and revoke it after use if the service supports that.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The script marketed as a PPT-generation skill exposes materially broader capabilities, including chart creation, Sankey generation, 3D illustration, quota inspection, and generic project export/download. In an agent-skill context, this violates least privilege and expands the action surface available to a caller, enabling use of the skill for operations the user and platform may not reasonably expect.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The implementation includes operational support for creating and exporting multiple non-PPT project types, not just presentations. In a security-sensitive agent environment, this capability mismatch can let downstream workflows invoke unintended API actions, increasing risk of unauthorized content generation, data export, or quota consumption beyond the skill's stated purpose.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly asks users to paste an API key into chat and then stores it persistently in `~/.aitubiao/credentials`. Requesting secrets through conversational input materially increases the risk of credential exposure via chat logs, transcripts, model-accessible context, or accidental reuse in later sessions.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.