Back to skill

Security audit

Alvis AI PPT Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple PPT-generation workflow for an external SkillBoss API, with privacy and language limitations users should understand before use.

Install only if you are comfortable providing a SkillBoss API key and sending PPT topics to SkillBoss API Hub. Do not include confidential business plans, private student data, or sensitive internal material unless you have reviewed the service's privacy terms. Also verify that the required scripts are included in the package you install, since this inspected artifact only contains SKILL.md.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documentation instructs the agent to send a user-provided PPT topic to the external SkillBoss API Hub but does not warn the user that their prompt content will leave the local environment. Topics can contain sensitive business plans, internal reports, student data, or other confidential material, so the omission creates a meaningful privacy and consent risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language guidance and category mappings are presented only with Chinese template/style names and example queries, with no indication that users may choose another language or locale. That can amount to an implicit locale constraint without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.