Back to skill

Security audit

AI PPT generate

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Baidu PPT-generation wrapper, but users should know their prompts, outlines, and document URLs are sent to Baidu.

Install only if you are comfortable using Baidu's Qianfan PPT service and providing a BAIDU_API_KEY. Do not submit confidential prompts, outlines, document URLs, or template URLs unless your organization permits sending that content to Baidu.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description promises an end-to-end intelligent PPT generation tool that can generate PPTs, let users choose themes/templates or customize templates, accept resource files, and return a download link for the final PPT. The supplied code chunk is narrower: it invokes Baidu's /generate_outline API and streams outline data only. While it does accept a query and optional resource URL plus some formatting/generation options, it does not create or return a completed PPT, does not expose template/custom-template features, and does not provide a download address. Therefore the code's actual behavior is materially more limited than the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a full intelligent PPT generation tool with multiple capabilities: creating PPTs from prompts, selecting/customizing templates, using uploaded resource files, and returning a download link for the final PPT. The supplied code does not perform PPT generation at all. It only fetches available PPT themes from a Baidu API endpoint (get_ppt_theme). This is related to PPT theming, but it is only a narrow support function and not an implementation of the declared end-to-end tool behavior. Therefore, the code chunk materially under-implements and differs from the declared primary purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises executable Python scripts that require environment access for the API key and network access to Baidu, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where reviewers and runtime policy may not clearly constrain what the skill is allowed to access, increasing the risk of unintended secret exposure or outbound requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description does not clearly warn that user prompts, outline content, and optional resource or template URLs are transmitted to Baidu's external service. This is a real privacy and data-handling issue because users or operators may provide sensitive business content, document links, or templates without understanding that the data leaves the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code sends query text, outline content, title, and optional resource/template URLs to a remote Baidu endpoint via requests.post. While the script names the API in code, it provides no confirmation prompt or user-facing warning that potentially sensitive user data will be transmitted off-system.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ppt_generate.py (reported line 34)May include surrounding context.

python
params["language_option"] = language_option
    if gen_mode:
        params["gen_mode"] = gen_mode
    with requests.post(url, headers=headers, json=params, stream=True) as response:
        response.raise_for_status()
        for line in response.iter_lines():
            line = line.decode('utf-8')

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ppt_outline_generate.py (reported line 31)May include surrounding context.

python
params["language_option"] = language_option
    if gen_mode:
        params["gen_mode"] = gen_mode
    with requests.post(url, headers=headers, json=params, stream=True) as response:
        response.raise_for_status()
        for line in response.iter_lines():
            line = line.decode('utf-8')

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends the user's query and optional resource URL to a remote Baidu API endpoint via requests.post. Although this network transmission is central to the script's function, there is no confirmation prompt, user-facing disclosure, or warning in the code that user content will be sent to an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.