Back to skill

Security audit

Seedream Ppt Maker

Security checks for vulnerabilities and agentic risk

Overview

This PPT skill is purpose-aligned overall, but it exposes part of a stored API key and makes live external API calls without enough user-facing control or disclosure.

Review this skill carefully before installing. It is not showing evidence of a backdoor or destructive behavior, but it can send your presentation content to Volces/Seedream, use your configured API key, consume paid API quota, and the install checker currently prints part of that key. Avoid using it with confidential or regulated material unless you accept that third-party processing, and remove the key-prefix logging before running the checker in any captured terminal or shared environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
check_install.py:65
Finding

API Key Material Is Exposed in Terminal and Automation Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
baoyu_seedream_ppt.py:82
Finding

Unvalidated API-Supplied Image URL Enables Server-Side Request Forgery and Resource Exhaustion

Content
View full analysis
0: image_url = result['data'][0]['url'] return image_url else: return None def download_image(url, save_path): try: resp = requests.get(url, timeout=60) if resp.status_code == 200: with open(save_path, 'wb') as f: f.write(resp.content) return True else: return False except Exception: return False ``` ### Technical Analysis The URL returned by the remote image-generation API is passed directly to `requests.get()` without validating: - URL scheme - Destination hostname - Resolved IP address - Redirect targets - Response `Content-Type` - Maximum response size - Whether the response is a valid image Although the initial API endpoint is the documented Volcengine service, the returned URL remains externally controlled data. If the upstream service, network path, account, or API response is compromised, the program can be directed to arbitrary HTTP or HTTPS destinations. Because `requests` follows redirects by default, validating only the initial URL would also be insufficient. A permitted host could redirect the request to loopback, private, link-local, or cloud metadata addresses. The response is loaded completely into memory through `resp.content` and then written without a size limit. A malicious or defective endpoint could therefore cause significant memory and disk consumption. A non-image response is also saved with a `.png` extension and subsequently passed to `python-pptx` image processing. ### Attack Path 1. The user submits presentation content for image generation. 2. The Skill sends the prompt to the configured Volcengine API endpoint. 3. An attacker ...[truncated 1535 chars]
Remediation
View remediation
maximum_size: raise ValueError("Image exceeds the download limit") output.write(chunk) ``` Hostname checks must be repeated after DNS resolution and for every redirect to reduce DNS rebinding and redirect-based bypass risks. ]]>

T08 · Insecure Dependencies

Note
Location
SKILL.md:25
Finding

Installation Instructions Use Unpinned Third-Party Dependencies

Content
View full analysis
Remediation
View remediation
--hash=sha256: requests== --hash=sha256: ``` Then document installation with: ```bash python3 -m venv .venv . .venv/bin/activate python3 -m pip install --require-hashes -r requirements.txt ``` The Skill dependency should likewise use the package manager’s supported immutable version or digest syntax rather than implicitly selecting the latest release. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior goes beyond simple PPT generation by reading ~/.openclaw/config.json for API credentials, performing connectivity checks, and reportedly displaying part of the API key. Accessing secrets and making outbound validation requests are sensitive actions; if not clearly disclosed and scoped, they can expose credentials or surprise users with data egress.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly promotes generating content through an external Seedream/Volces API and instructs users to configure an API key, but it does not warn that presentation content may be transmitted to a third-party service. In a PPT-generation workflow, users may submit internal business plans, product roadmaps, or personal data, so the missing privacy notice can lead to inadvertent data disclosure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill instructs execution of Python scripts that read local files, write output artifacts, and make network requests, but it declares no explicit tool scope or permissions. This weakens sandboxing and user transparency, increasing the chance the skill can access local configuration and external services without clear consent boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language content of the skill consistently uses Chinese for the description, triggers, and operating instructions, but it does not state that the user can choose another language. This can amount to forcing a specific language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes a very generic phrase, "生成PPT", which could match many ordinary conversations about making presentations rather than intentional invocation of this specific skill. The description does not provide exclusions, context limits, or negative examples to narrow when the skill should activate.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This code performs external network transmission of prompt data to a remote API endpoint. External transmission is expected for an image-generation skill, but it remains security-relevant because the transmitted content may include sensitive user material and there are no trust-boundary warnings or consent controls in the workflow.

Content

Scanner excerpt · baoyu_seedream_ppt.py (reported line 69)May include surrounding context.

python
"size": resolution
    }
    
    response = requests.post(
        f"{BASE_URL}/images/generations",
        headers=headers,
        json=data,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool sends user content and fully assembled prompts to a third-party image-generation API, but it provides no explicit disclosure or consent mechanism before transmitting potentially sensitive material off-host. In the context of a PPT generator that may process internal business content, this creates a real confidentiality and privacy risk through unintended remote sharing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description explicitly says the skill supports an interactive staged confirmation process to reduce repeated edits and API usage. In this file, main() reads inputs, generates prompts, calls the image API for every page, downloads results, and builds the PPT without any interactive confirmation checkpoints or review loop.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code forcibly replaces the language placeholder with "Chinese" for all generated prompts. This is a natural-language locale constraint with no opt-in, override flag, or explanation that the tool is intended only for a China-specific workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script prints the first 20 characters of the API key to the console, which is unnecessary secret disclosure. Console output may be captured by terminal logs, screenshots, CI logs, shell history wrappers, or remote support sessions, allowing partial credential leakage that can aid key identification or correlation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script automatically uses the user's stored API credential to make a live request to an external service as part of an install check. Although testing connectivity is a legitimate goal, transmitting credentials during installation verification without clear opt-in, dry-run mode, or prominent disclosure can surprise users and trigger unintended external account usage, logging, or billing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This duplicate finding identifies the same outbound transmission behavior: the script sends a test image-generation request to an external endpoint with authorization headers. The risk is contextual rather than overtly malicious, but in a setup verifier it still creates privacy, billing, and transparency concerns.

Content

Scanner excerpt · check_install.py (reported line 83)May include surrounding context.

python
"prompt": "test",
                    "size": "2560x1440"
                }
                response = requests.post(
                    "https://ark.cn-beijing.volces.com/api/v3/images/generations",
                    headers=headers,
                    json=data,

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This duplicate finding identifies the same outbound transmission behavior: the script sends a test image-generation request to an external endpoint with authorization headers. The risk is contextual rather than overtly malicious, but in a setup verifier it still creates privacy, billing, and transparency concerns.

Content

Scanner excerpt · check_install.py (reported line 83)May include surrounding context.

python
"prompt": "test",
                    "size": "2560x1440"
                }
                response = requests.post(
                    "https://ark.cn-beijing.volces.com/api/v3/images/generations",
                    headers=headers,
                    json=data,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file is a code file, so SQP-3 applies to natural-language policy issues in code literals and behavior. The prompt template forcibly replaces {{LANGUAGE}} with "Chinese", which imposes a specific language/locale on all generated output without any user opt-in or documented region-specific justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code comments imply user-modified prompts may be reused, but the implementation discards those edits and generates fresh prompts. In a skill designed around stepwise human confirmation to save quota and avoid repeated mistakes, this is a workflow-integrity flaw that can silently override reviewed content and send different data to the external model than the user approved.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code comments imply user-modified prompts may be reused, but the implementation discards those edits and generates fresh prompts. In a skill designed around stepwise human confirmation to save quota and avoid repeated mistakes, this is a workflow-integrity flaw that can silently override reviewed content and send different data to the external model than the user approved.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

A skill description that effectively forces a single language can violate language/locale policy when no opt-in or alternative is provided. This README presents all user-facing instructions exclusively in Chinese and does not mention language options or a justified region-specific scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill's stated purpose is generating image-based PPTs from content, layout, and style inputs. Reading credentials from ~/.openclaw/config.json reaches beyond the immediate document-processing task and introduces access to broader user-scoped configuration data that the manifest description does not mention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script's docstrings and all printed messages are in Chinese, with no user opt-in or explanation that the skill is intended only for Chinese-speaking users. This can violate a language/locale policy when a skill mandates a specific language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is written entirely in Chinese and describes the skill in a way that implies a fixed Chinese-language experience, without indicating any language choice or opt-in. This can be a natural-language policy concern when a skill appears to impose a specific language or locale without documenting flexibility or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.